Skip to content

Log Channels

Configuring Event Log Channels for Forwarding

Event log channels define which events are collected and forwarded from a source system to the collector. By default, Windows logs events to channels like Application, Security, and System, but custom channels can be created to target specific event sources or categories. Proper configuration ensures only relevant events are forwarded, reducing bandwidth usage and improving operational efficiency.


Step 1: Identify Events to Forward

Before configuring channels, determine which events (or event IDs) should be forwarded. Use Get-WinEvent to analyze logs and identify patterns:

Get-WinEvent -FilterXPath "Event[System[EventID=4624]]" | Format-List
This example retrieves successful logon events (Event ID 4624) for analysis.


Step 2: Create Custom Event Log Channels (Optional)

Custom channels can be created via the registry or using PowerShell. For advanced filtering, modify the registry:

  1. Registry Path:
    HKLM\SYSTEM\CurrentControlSet\Services\EventLog\<LogName>
    Replace <Log,Name> with a new channel name (e.g., CustomSecurity).

  2. Create a New Channel:
    Use New-Item to add a new log entry:

    New-Item -Path "HKLM:\SYSTEM\CurrentControlSet\Services\EventLog\CustomSecurity" -Force
    
    Set the EventMessageFile value to the path of the event message file (e.g., %SystemRoot%\system32\eventlog.dll).

  3. Verify the Channel:
    Open Event Viewer > Windows Logs and confirm the new channel exists.


Step 3: Configure Event Subscriptions to Use Channels

Event subscriptions define which events are forwarded. Use the Event Subscriptions tool or PowerShell to associate channels:

  1. Using Event Viewer:
  2. Open Event Viewer > Windows Logs > Subscriptions.
  3. Right-click Subscriptions > Create Subscription.
  4. In the Subscription Settings dialog, select the desired channels (e.g., Security, CustomSecurity) and specify the collector server.

  5. Using PowerShell:
    Create a subscription XML file that includes channel definitions. Example:

    <QueryList>
      <Query Id="1" Path="Security">
        <Select>*</Select>
      </Query>
      <Query Id="2" Path="CustomSecurity">
        <Select>*</Select>
      </Query>
    </QueryList>
    
    Save this as CustomSubscription.xml and use New-EventLogSubscription to apply it.


Step 4: Validate Forwarding Configuration

Ensure events are being forwarded by:
1. Checking the collector’s Event Viewer for incoming logs.
2. Using Get-WinEvent on the source to confirm events are being logged.
3. Monitoring the collector’s Forwarded Events log for errors.


Key takeaways

  • Event channels act as filters for which events are forwarded, reducing unnecessary data.
  • Custom channels can be created via the registry for granular control.
  • Subscriptions must explicitly reference channels to enable forwarding.
  • Always validate configurations using both source and collector logs.
  • PowerShell and Event Viewer provide complementary tools for managing channels and subscriptions.