Enabling WinRM
Windows Event Forwarding relies on WinRM (Windows Remote Management) to securely transmit event logs from source servers to a centralized event collector. Enabling WinRM correctly ensures reliable and secure communication. This section outlines the steps to configure WinRM for event forwarding.
Enabling the WinRM Service¶
The WinRM service must be running and configured to accept remote connections.
-
Start and set the service to automatic:
Verify the service status:
-
Configure WinRM settings:
This enables HTTP (port 5985) and HTTPS (port 5,986) listeners. For HTTPS, ensure a valid certificate is installed (see next section).
UseSet-WSManQuickConfigfor a basic setup (HTTP/HTTPS):
Configuring WinRM Listeners¶
For secure event forwarding, configure WinRM to use HTTPS with a trusted certificate.
-
Create a self-signed certificate (for testing):
Replace
"localhost"with your server’s FQDN if needed. -
Register the certificate with WinRM:
-
Verify listener configuration:
Ensure the collector server’s IP/FQDN is added to trusted hosts if required.
Firewall Configuration¶
Allow WinRM traffic through the firewall.
-
Check existing rules:
-
Add rules for HTTP/HTTPS (if missing):
-
Ensure the firewall is not blocking traffic:
Disable "Block all incoming connections" if necessary.
Testing WinRM Connectivity¶
Verify the configuration with:
Security Best Practices¶
- Use HTTPS: Always enable HTTPS with a trusted certificate (avoid self-signed certs in production).
- Restrict access: Limit WinRM to trusted IPs or networks using firewall rules.
- Audit logs: Monitor event logs for unauthorized access attempts (Event ID 4104).
Key takeaways¶
- WinRM must be enabled and configured for HTTPS to secure event forwarding.
- Firewall rules for ports 5985 (HTTP) and 5986 (HTTPS) are critical.
- Use trusted certificates and restrict access to prevent unauthorized connections.
- Regularly test connectivity and audit logs for security compliance.