syslog-ng-users January 2011 archive
Main Archive Page > Month Archives  > syslog-ng-users archives
syslog-ng-users: Re: [syslog-ng] Syslog-ng Windows Agent & W

Re: [syslog-ng] Syslog-ng Windows Agent & WIN2008 Event Forwarding Subscription

From: Martin Holste <mcholste_at_nospam>
Date: Sat Jan 22 2011 - 03:23:54 GMT
To: Zoltán Pallagi <pzolee@balabit.hu>

> I am not sure that these programs can forward events coming from
> other windows forwarded by WinRM. (so these events are in
> ForwardedEvents store on the server, and syslog-ng agent forward
> these forwarded events to a syslog-ng).
>
> Can you confirm that these programs can do it?
>

I have not tried EvtSys with subscriptions, but I know that by default
it will forward all sources (Security, Application, etc.) including
any custom or otherwise non-standard sources. If ForwardedEvents is
considered a source, it will be forwarded along with everything else.
I should also point out that you can configure EvtSys to filter out
messages in a granular way with some registry keys if you don't want
everything.
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html