WEF Architecture Components
Windows Event Forwarding (WEF) relies on three core components to enable centralized event collection and distribution. These components work together to ensure events are captured, filtered, and forwarded to designated destinations for analysis and monitoring.
Event Collector¶
The Event Collector is a role within the Windows Event Log service that acts as a centralized hub for collecting events from local or remote sources. It processes event subscriptions and routes events to their designated destinations, such as a Security Information Management (SIM) system or a SIEM tool.
- Role: Aggregates events from multiple sources based on subscription rules.
- Function: Filters events using criteria defined in subscriptions and forwards them to the specified collector.
- Configuration: Managed via the Event Viewer or PowerShell cmdlets like
New-EventLogSubscription.
Example:
# Create a subscription to forward events from the "Security" log to a collector
New-EventLogSubscription -Name "SecurityForwarding" -CollectorComputer "CollectorServer" -LogName "Security" -ForwardingMode RealTime
Event Log Subscriptions¶
Event Log Subscriptions define the rules for forwarding events from a source to a collector. They specify which events to include, the destination (collector), and the frequency of forwarding (real-time or near-real-time).
- Key Parameters:
- Source: The event log or provider generating events (e.g., "Security", "System").
- Destination: The collector computer that receives the events.
- Filtering: Optional criteria to include/exclude specific events (e.g., event IDs, levels).
- Types:
- Real-Time: Events are forwarded immediately.
- Near-Real-Time: Events are batched and sent periodically.
Example:
Forwarding Providers¶
Forwarding Providers are the sources of events that are forwarded to the collector. These can be local or remote systems, and they include:
- Windows Event Log Providers: Local or remote systems using the Event Log service.
- Third-Party Providers: Applications or services that generate events and support WEF integration.
- Role: Generate events and push them to the collector based on subscription rules.
- Configuration: Requires enabling the "Event Log Subscription" feature on the source system.
Example:
# Verify if a source system is configured as a forwarding provider
Get-WinEvent -ListProvider | Where-Object { $_.Name -eq "Microsoft-Windows-Security-Auditing" }
Key takeaways¶
- Event Collectors centralize event aggregation and filtering.
- Subscriptions define the rules for forwarding events to collectors.
- Forwarding Providers generate events and push them to collectors based on subscription criteria.
- These components enable scalable, policy-driven event management across distributed Windows environments.