Guide To Configuring Event Subscriptions In Server 2008

Written by Allen White on. Posted in SBS2008/2011, Server 2008

To set up a source initiated subscription that requires minimal intervention and no thought every time a new server is built, follow these easy steps.

Source computers

If you want to configure this as a one off, to test do the following:

On your source computer, using an elevated command prompt, enter the following:

winrm qc -q

Or if you are running in a domain environment, and want to set and forget:

  1. Open up your Group Policy Editor, and browse to (or create a new) GPO that will contain your settings (best bet here is to use a GPO already in place for your servers so that you don’t create load for each machine processing a million GPO’s!).
  2. Under the Computer Configuration node, expand the Administrative Templates node, then expand the Windows Components node, and then select the Event Forwarding node.
  3. Right-click the Subscription Manager setting, and select Properties. Enable the Subscription Manager setting, and click the Show button to add a server address to the setting. Add at least one setting that specifies the event collector computer. The Subscription Manager Properties window contains an Explain tab that describes the syntax for the setting.
  4. Now browse down the list a little way, and find the Windows Remote Management (WinRM) node, select the WinRM Service node, and find the “Allow Automatic Configuration of Listners” setting.
  5. Enable the setting, and then enter in an IP, IP range, or enter * into each of the IPv4 and IPv6 fields. Just use * if you aren’t concerned about security, or drill down to specifics if you are doing things by the book as you should be!
  6. Close out of the GP editor, and then just refresh the settings tab to make sure that everything is the way that you want it to be.

At this stage you can run gpupdate /force on your source servers, or just allow for the natural flow and wait for the next automatic refresh.

Collector Computer

Run the following command from an elevated privilege command prompt to configure Windows Remote Management:

winrm qc -q

Run the following command to configure the Event Collector service:

wecutil qc /q

You now have 2 options about how you create the subscription. You can either do this through the event viewer, or by using a script.

Via the Event viewer:

  1. Open up the event viewer, and select the subscriptions node. Right click, and select “Create Subscription”
  2. Give the subscription a name, and select “Source computer initiated”
  3. Select “Select Computer Groups” and enter it in domain computers, as per the example below.

 

4. If you are using certificates, select the one for your system, and select OK.

5.  Hit “Select events” and chose the event types and ID’s that you want to monitor, select OK, and if you are happy with your settings, select OK again.

Via a script

Copy the following code into your favourite text editor, and save it as configurationfile.xml



Custom



1
1000




2018-01-01T00:00:00.000Z


]]>

true
http
RenderedText

ForwardedEvents

O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS)

From the command line browse to the folder that you saved the above file in, and run:

wecutil cs configurationFile.xml

 

 
Allen White
Allen is a Consultant for ITPS in the North East of England and holds the following accreditations. MCSA, MCSE, MCTS, MCITP, CCA, CCSP, VCP 4,5 and HP ASE, AIS - Network Infrastructure.

ITPS provides strategic IT consultancy, implementation, data centre provision and unified communications, as well as support services and workspace and disaster recovery. If you require a consultation then please contact me via the contacts section or direct on 07931222991, add me on linkedin. https://uk.linkedin.com/in/allenwhiteconsultant0001

Tags:

Leave a comment

Categories

(c) Techieshelp.com. Please be aware, all information is provided freely, any information used is done so at your risk and Techieshelp will not be held responsible for any issue that may occur.
!-- BuySellAds On-Site Shopping Cart -->