Skip to content

Architecture & Workflow

Windows Event Forwarding (WEF) is a core component of Windows event log management, enabling centralized collection and analysis of events across distributed systems. The architecture is built on three primary roles: Event Sources (systems generating events), Event Forwarding Server (intermediary for routing), and Event Collectors (destinations for aggregated events). This section outlines the architecture and workflow of WEF, emphasizing its role in secure, scalable event management.


Architecture Overview

The WEF architecture consists of the following key components:

  1. Event Sources:
    Windows systems (servers, workstations) that generate events (e.g., security logs, application logs). These systems must have the Event Log service and Event Forwarding feature enabled.

  2. Event Forwarding Server:
    Acts as an intermediary to route events from sources to collectors. It uses the Event Log service to forward events over the network. This server is typically a Windows Server with the Event Forwarding role installed.

  3. Event Collectors:
    Systems that receive and process forwarded events. Collectors can be:

  4. Local collectors (e.g., a SIEM system like Splunk or Microsoft Sentinel).
  5. Remote collectors (e.g., another Windows Server acting as a central log repository).

  6. Event Log Management Tools:
    Tools like Event Viewer, PowerShell, or XML configuration files are used to define forwarding rules and subscriptions.


Event Forwarding Workflow

The event forwarding workflow proceeds in these steps:

  1. Event Generation:
    An event is generated on a source system (e.g., a Windows Server) and written to the local event log.

  2. Event Subscription:
    A subscription is configured on the source system to forward specific events. Subscriptions define:

  3. Which events to forward (e.g., Event ID 4625 for failed logon attempts).
  4. The destination collector (e.g., an IP address or hostname).
  5. Filtering criteria (e.g., event levels, categories).

  6. Event Forwarding:
    The source system sends the event to the Event Forwarding Server using Secure Sockets Layer (SSL) or Transport Layer Security (TLS) for encryption. The server acts as a relay, forwarding events to the designated collector.

  7. Event Collection:
    The collector receives the event, stores it in its event log, and processes it (e.g., indexing for search, alerting, or forwarding to a SIEM system).

  8. Event Analysis:
    Analysts query the collector’s event logs to investigate incidents, monitor compliance, or detect threats.


Configuration Examples

1. Creating a Subscription via PowerShell

# Create a subscription to forward Event ID 4625 to a remote collector
New-WinEventSubscription -Name "FailedLogonAlert" -EventID 4625 -Collector "CollectorServer01" -TransportType HTTPS

2. Configuring Forwarding via Event Viewer

  1. Open Event Viewer > Windows Logs > Forwarded Events.
  2. Right-click > Create Subscription.
  3. Specify the event source, filter criteria, and destination collector.

3. Verifying Forwarding Rules

Get-WinEventSubscription | Format-List

Key takeaways

  • WEF architecture relies on three roles: sources, forwarding servers, and collectors, with secure transport between components.
  • Event subscriptions define which events are forwarded, their filters, and destination collectors.
  • PowerShell cmdlets like New-WinEventSubscription and Get-WinEventSubscription simplify configuration and management.
  • Encryption (HTTPS/TLS) ensures secure event transmission across the network.
  • Collectors can be local or remote, enabling centralized log analysis and compliance reporting.