Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To configure Windows Event Forwarding (WEF) in Windows Server 2012 R2, enable WinRM on the source computers and collector, configure the collector’s Windows Event Collector service, create a subscription, and point sources to it with Group Policy. Then verify subscription status with wecutil and confirm matching events arrive in the collector’s log. A subscription will not deliver events unless both the sources and collector are configured.

How Windows Event Forwarding works

WEF uses WinRM for communication from event sources to a collector. The Windows Event Collector service receives subscriptions. In a source-initiated setup, you define a subscription on the collector, while source computers learn where to connect through the Event Forwarding SubscriptionManager Group Policy setting. This avoids listing every source computer in the subscription itself. Microsoft describes this approach in Setting up a Source Initiated Subscription.

The configuration has two sides: sources need WinRM and the collector address, while the collector needs its collection service configured and a subscription with a suitable event query and allowed sources.

Configure a source-initiated subscription for domain computers

1. Enable WinRM on the source computers

From an elevated command prompt on each source, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

winrm qc -q

For a production fleet, use administrative policy or another managed deployment method rather than configuring machines individually.

2. Point sources to the collector with Group Policy

In Group Policy Management, edit the policy that applies to the source computers and go to Computer Configuration > Administrative Templates > Windows Components > Event Forwarding > SubscriptionManager. Configure the setting so the sources contact the event collector. Apply the policy on a test source with:

gpupdate /force

3. Configure the collector

On the collector, run these commands from an elevated prompt:

winrm qc -q

wecutil qc /q

The first configures WinRM; the second configures the Windows Event Collector service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Create and tune the subscription

On the collector, create a source-initiated subscription in Event Viewer, or save a subscription definition as XML and register it with:

wecutil cs configurationFile.xml

Set the event query, allowed sources, destination log, and delivery behavior. Microsoft’s example uses the ForwardedEvents log. Test with a narrow query and a small set of sources before expanding the policy to a larger group.

5. Verify configuration and delivery

Use the subscription ID shown in Event Viewer or the subscription definition. Check runtime status and configured details with:

wecutil gr <subscriptionID>

wecutil gs <subscriptionID>

gr reports runtime status; gs displays subscription settings. Generate events on an allowed source that match the query, allow the configured delivery behavior time to send them, then inspect ForwardedEvents or the selected destination log on the collector. A successful connection alone does not prove that the event query matches or that events are reaching the intended log.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Forwarding the Security log

To forward Security events, Microsoft’s source-initiated setup guidance says to add NETWORK SERVICE to the source computer’s Event Log Readers group. Include this permission on the applicable source computers, then verify that events matching the subscription query appear on the collector.

Choose delivery behavior for latency and bandwidth

Windows Server 2012 R2 documentation describes three subscription delivery modes. The listed intervals are configuration values, not performance guarantees: actual delivery also depends on subscription settings, source and collector load, and the network. Microsoft notes that forwarding takes time after events are generated and warns that source events must not be overwritten before they are forwarded. See Best practice for configuring EventLog forwarding in Windows Server 2012 R2.

Mode Documented behavior When it fits
Normal Pull delivery; batches five items and uses a 15-minute batch timeout. Microsoft’s general default choice when tighter bandwidth control or faster delivery is not required.
Minimize Bandwidth Push delivery; six-hour batch timeout and six-hour heartbeat interval. When reducing how often sources connect is more important than prompt delivery.
Minimize Latency Push delivery; 30-second batch timeout. Alerting or critical-event scenarios where faster forwarding matters.

Multiple subscriptions can multiply source-to-collector connections. Where the same sources need related events, consolidate compatible XPath queries into one subscription when practical. Microsoft also cautions that default Normal behavior can cause high memory use at 2,000 to 4,000 clients per collector; treat this as a planning observation from its guidance, not a capacity guarantee for every deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Configure sources outside the collector’s domain

For sources outside the collector’s domain, Microsoft documents certificate-based HTTPS forwarding. This requires more than changing the SubscriptionManager address: certificates, trust, the collector listener, and certificate mapping must all be configured consistently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The collector needs a server-authentication certificate whose subject matches its FQDN.
  • Each source needs a client-authentication certificate whose subject matches that source’s FQDN.
  • Configure the collector’s HTTPS listener and certificate authentication, establish the required certificate trust and mapping, and open the documented HTTPS endpoint.
  • Set the source SubscriptionManager address in this form, using the collector’s FQDN, refresh interval, and issuing CA thumbprint:
    Server=HTTPS://<FQDN>:5986/wsman/SubscriptionManager/WEC,Refresh=<seconds>,IssuerCA=<issuer-thumbprint>

Verify the connection and certificate chain before depending on the forwarding path. In Microsoft’s certificate-based scenario, source event 104 indicates a successful connection to the subscription manager and event 100 indicates that the subscription was created. If authentication fails, inspect the certificate-related logs as well as the subscription status.

Troubleshoot missing forwarded events

  • No source appears connected: Confirm WinRM is configured on both ends, the source received the SubscriptionManager policy, and the collector’s Windows Event Collector service was configured with wecutil qc /q.
  • The subscription is active but the destination is empty: Check the event query, allowed sources, and destination log. Generate an event that actually matches the filter, then allow for the selected delivery mode’s batching behavior.
  • Security events are absent: Confirm NETWORK SERVICE belongs to Event Log Readers on the source, and ensure the subscription query includes the Security events you expect.
  • Non-domain authentication fails: Check certificate subject names, client/server authentication purposes, trust chain, HTTPS listener, and certificate mapping. Use source events 104 and 100 as connection and subscription-creation indicators.
  • Events disappear before collection: Review source log retention and forwarding timing. Microsoft warns that events can be overwritten before the forwarding mechanism sends them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.