mag72

Event Log Forwarding (Windows) to Syslog

event log fowarding to syslog from windows server

Event log forwarding is a good way to consolidate all event logs in a central location or to a central server (Syslog, etc.) to reduce the hassle of logging into every server and checking logs individually. There are several ways of accomplishing this task in your windows environment, either natively using WinRM and powershell commands or using software that will automatically configure all aspects of forwarding for you. We’ll go over the basics of forwarding via a software solution.

A couple benefits to forward event logs in windows are as follows:

  1. Specify Certain Events to be Forwarded by ID, source, Type or whatever other parameter you would like to specify.
  2. Store Events for Auditing purposes.
  3. Consolidate and Filter Events in One Location/Server.

Before you start:

Grab a Free copy of Kiwi Syslog server and install it on the machine you would like to dedicate to Syslog.

Software Solution

Now lets install the FREE software utility provided by Solarwinds called “Event Log Forwarder for Windows“. Lets grab the download from HERE and get it installed on all Windows Servers you want to Forward event logs from.

After installation is finished and you’ve started the Application, you will see the main screen as highlighted below:

event log fowarder dashboard screenshot

Now select ADD button and select which Event logs you would like to forward to your Syslog server.

choose your event sources to forward

You also have the option to dial down into Event Sources, Specify with Events to Exclude/Include, Keywords to filter by, Users or Computers to filter. You can filter by Multiple parameters on this screen.

filtering options

Now click NEXT to move onto the next Screen to finish up the process.

last screen

Add Syslog Server

Now that you’ve setup the forwarding feature, we’ll need to specify the Syslog server that we want to send event logs to.

Click on the “Syslog Servers” tab and click the “Add” button to specify an IP Address, Port and other pertinent information regardless you syslog server as seen below:

click the add button

add syslog server

Now that you’ve added your syslog server information, if needed, you may also send some Test events using the “TEST” tab at the top to ensure everything is configured properly.

test the forwarding of event logs

This utility should be installed on all your Windows servers that you would like to forward event logs to a Syslog server. It has a small-footprint and runs silently in the system tray without much user intervention needed.

Downloads

Kiwi Syslog Server FREE Edition

Download Kiwi Syslog Server

Event Log Forwarder Utility FREE

Download Event Log Forwarder Utility