Skip to content
/ owinec Public

An open-source log collector for collecting logs from Windows Event Forwarding

License

Notifications You must be signed in to change notification settings

NerLOR/owinec

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

56 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Open Windows Event Collector (Owinec)

Open Windows Event Collector, in short Owinec, is a server application, where Windows hosts can forward their events to. Owinec is based on source initiated log forwarding from either domain-joined or non-domain-joined Windows hosts.

Windows Configuration

Verify that NT Authority\Network Service is a member of the Event Log Readers group on the source computer.

Computer Configuration/Administative Templates/Windows Components/Event Forwarding/Configure Target Subscription Manager

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\EventForwarding\SubscriptionManager

References

  1. [WS-MAN] Web Services Management, DMTF
  2. [MS-WSMV] Web Services Management Protocol Extensions for Windows Vista, Microsoft
  3. [MS-NLMP] NT LAN Manager (NTML) Authentication Protocol, Microsoft