To configure Windows Event Forwarding (WEF) in Windows Server 2012 R2, enable WinRM on the source computers and collector, configure the collector’s Windows Event Collector service, create a subscription, and point sources to it with Group Policy. Then verify subscription status with wecutil and confirm matching events arrive in the collector’s log. A subscription will not deliver events unless both the sources and collector are configured.
How Windows Event Forwarding works
WEF uses WinRM for communication from event sources to a collector. The Windows Event Collector service receives subscriptions. In a source-initiated setup, you define a subscription on the collector, while source computers learn where to connect through the Event Forwarding SubscriptionManager Group Policy setting. This avoids listing every source computer in the subscription itself. Microsoft describes this approach in Setting up a Source Initiated Subscription.
The configuration has two sides: sources need WinRM and the collector address, while the collector needs its collection service configured and a subscription with a suitable event query and allowed sources.
Configure a source-initiated subscription for domain computers
1. Enable WinRM on the source computers
From an elevated command prompt on each source, run:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
winrm qc -q
For a production fleet, use administrative policy or another managed deployment method rather than configuring machines individually.
2. Point sources to the collector with Group Policy
In Group Policy Management, edit the policy that applies to the source computers and go to Computer Configuration > Administrative Templates > Windows Components > Event Forwarding > SubscriptionManager. Configure the setting so the sources contact the event collector. Apply the policy on a test source with:
gpupdate /force
3. Configure the collector
On the collector, run these commands from an elevated prompt:
winrm qc -q
wecutil qc /q
The first configures WinRM; the second configures the Windows Event Collector service.
Recommended Free Tools
4. Create and tune the subscription
On the collector, create a source-initiated subscription in Event Viewer, or save a subscription definition as XML and register it with:
wecutil cs configurationFile.xml
Set the event query, allowed sources, destination log, and delivery behavior. Microsoft’s example uses the ForwardedEvents log. Test with a narrow query and a small set of sources before expanding the policy to a larger group.
5. Verify configuration and delivery
Use the subscription ID shown in Event Viewer or the subscription definition. Check runtime status and configured details with:
wecutil gr <subscriptionID>
wecutil gs <subscriptionID>
gr reports runtime status; gs displays subscription settings. Generate events on an allowed source that match the query, allow the configured delivery behavior time to send them, then inspect ForwardedEvents or the selected destination log on the collector. A successful connection alone does not prove that the event query matches or that events are reaching the intended log.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Forwarding the Security log
To forward Security events, Microsoft’s source-initiated setup guidance says to add NETWORK SERVICE to the source computer’s Event Log Readers group. Include this permission on the applicable source computers, then verify that events matching the subscription query appear on the collector.
Choose delivery behavior for latency and bandwidth
Windows Server 2012 R2 documentation describes three subscription delivery modes. The listed intervals are configuration values, not performance guarantees: actual delivery also depends on subscription settings, source and collector load, and the network. Microsoft notes that forwarding takes time after events are generated and warns that source events must not be overwritten before they are forwarded. See Best practice for configuring EventLog forwarding in Windows Server 2012 R2.
| Mode | Documented behavior | When it fits |
|---|---|---|
| Normal | Pull delivery; batches five items and uses a 15-minute batch timeout. | Microsoft’s general default choice when tighter bandwidth control or faster delivery is not required. |
| Minimize Bandwidth | Push delivery; six-hour batch timeout and six-hour heartbeat interval. | When reducing how often sources connect is more important than prompt delivery. |
| Minimize Latency | Push delivery; 30-second batch timeout. | Alerting or critical-event scenarios where faster forwarding matters. |
Multiple subscriptions can multiply source-to-collector connections. Where the same sources need related events, consolidate compatible XPath queries into one subscription when practical. Microsoft also cautions that default Normal behavior can cause high memory use at 2,000 to 4,000 clients per collector; treat this as a planning observation from its guidance, not a capacity guarantee for every deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Configure sources outside the collector’s domain
For sources outside the collector’s domain, Microsoft documents certificate-based HTTPS forwarding. This requires more than changing the SubscriptionManager address: certificates, trust, the collector listener, and certificate mapping must all be configured consistently.
- The collector needs a server-authentication certificate whose subject matches its FQDN.
- Each source needs a client-authentication certificate whose subject matches that source’s FQDN.
- Configure the collector’s HTTPS listener and certificate authentication, establish the required certificate trust and mapping, and open the documented HTTPS endpoint.
- Set the source SubscriptionManager address in this form, using the collector’s FQDN, refresh interval, and issuing CA thumbprint:
Server=HTTPS://<FQDN>:5986/wsman/SubscriptionManager/WEC,Refresh=<seconds>,IssuerCA=<issuer-thumbprint>
Verify the connection and certificate chain before depending on the forwarding path. In Microsoft’s certificate-based scenario, source event 104 indicates a successful connection to the subscription manager and event 100 indicates that the subscription was created. If authentication fails, inspect the certificate-related logs as well as the subscription status.
Quick Recap
Troubleshoot missing forwarded events
- No source appears connected: Confirm WinRM is configured on both ends, the source received the SubscriptionManager policy, and the collector’s Windows Event Collector service was configured with
wecutil qc /q. - The subscription is active but the destination is empty: Check the event query, allowed sources, and destination log. Generate an event that actually matches the filter, then allow for the selected delivery mode’s batching behavior.
- Security events are absent: Confirm
NETWORK SERVICEbelongs to Event Log Readers on the source, and ensure the subscription query includes the Security events you expect. - Non-domain authentication fails: Check certificate subject names, client/server authentication purposes, trust chain, HTTPS listener, and certificate mapping. Use source events 104 and 100 as connection and subscription-creation indicators.
- Events disappear before collection: Review source log retention and forwarding timing. Microsoft warns that events can be overwritten before the forwarding mechanism sends them.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

