 |
 |
 |
|
 |
Zubair Alexander
|
|
|
 |
 |
Configuring a Central Event Collector Computer |
How can I collect events from various Windows Vista computers to a central event collector computer? |
by Zubair Alexander |
4/16/2008 -- You can use the new event-forwarding feature in Vista to forward events from multiple Vista computers to one central collector computer. Here's the procedure.
Assuming the computers are part of the domain and you have administrative access to all the computers -- both source and destination -- you need to configure event subscriptions in the Event Viewer. I recommend using the domain administrator account.
First of all you need to configure the Windows Remote Management service. This service was first shipped in Windows Server 2003 R2 and has been enhanced in Vista.
- On the collector computer, as well as on all the source computers, go to the command prompt and type "winrm quickconfig" (without the quotes). Type Y and press enter to configure the service. You'll notice that it configures the Windows Remote Management service, creates a WinRM listenter and enables WinRM firewall exception, if necessary.
- On the collector computer, configure the Windows Event Collector service by typing "WECutil QC" (again, without quotes) at the command prompt. Click Y to configure the service. "QC" stands for "quick config." You can type wecutil /? to see other options.
- Add the collector computer's computer account to the local Administrators group on all the source computers.
- On the collector computer, start Event Viewer and click on the Subscriptions node.
- Right-click Subscriptions and click Create Subscription. If Windows Event Collector service isn't running on the computer, you'll be prompted to configure and start the service. Select Yes.
- Type a name for the subscription.
- Click Add to add the source Vista computers whose events you want to collect.
- Click Select Events and choose the options you want.
- Click the Advanced button and, under User Account, select Specific User. Enter the credentials for the user.
- Click OK a couple of times to finish creating your subscription.
You have now configured your central collector computer to accept forwarded events from other Vista computers.
|
Zubair Alexander, MCSE, MCT, MCSA and Microsoft MVP is the founder of SeattlePro Enterprises, an IT training and consulting business. His experience covers a wide range of spectrum: trainer, consultant, systems administrator, security architect, network engineer, author, technical editor, college instructor and public speaker. Zubair holds more than 25 technical certifications and Bachelor of Science degrees in Aeronautics & Astronautics Engineering, Mathematics and Computer Information Systems. His Web site, www.techgalaxy.net, is dedicated to technical resources for IT professionals. Zubair may be reached at .
|
|
|
 |
More articles by Zubair Alexander:
|
There is 1 user Comments for “Configuring a Central Event Collector Computer”
|
Page 1 of 1
|
6/5/12: Ammiratore from XesSHhugeMrq says: |
Hey Chris, will you have an artbook of snkaes at your store ? I buy it the minuit he is online. btw. the prints i bought looking good on my wall. Thanks and greetz from Belgium. |
|
|
|
|