Set Up Windows Event Forwarding
USM Anywhere provides the log forwarding policy that you use to set up the WEF on your Windows Server. To get the USM Anywhere log forwarding policy- In USM Anywhere, go to Data Sources > Sensors.
- Click the Sensor Apps tab.
- In the left navigation list, select Windows Event Collector.
- Select the USM Anywhere Sensor where you enabled the WEC sensor app.
-
Copy the policy from the field labeled Log Forwarding Policy. You will use this in the next procedure to configure the policy on your Windows Server. The policy follows this pattern:
- On the Windows Server, go to the Control Panel and open the Local Group Policy Editor.
- Select Computer Configuration > Administrative Templates > Windows Components > Event Forwarding, and then click Configure Target Subscription Manager.
- Click the Edit policy setting link.
- In the Configure Target Subscription Manager window, make sure that the subscription is marked as Enabled.
- In the Options section of the window, click Show to open the subscription managers.
- In the new Show Contents window, paste the policy that you copied from USM Anywhere in the previous procedure into the new subscription Value field.
- Click OK and close the Local Group Policy Editor.
-
Open the terminal and apply the new configurations by entering this:
Verify the Windows Event Log Collection
You can verify that your Windows Event Log collection configurations are correct by reviewing the event logs. To review the Windows Event Logs- On the Windows Server, open the Event Viewer.
- Go to Applications and Services Logs > Microsoft > Windows > Eventlog-ForwardingPlugin and check for any errors. You might see warnings if there are any paths that are not configured on your Windows Servers.