Stream Encryption
Windows Event Forwarding (WEF) relies on secure communication between event sources and collectors to protect sensitive data in transit. Enabling TLS (Transport Layer Security) encryption ensures that event data is encrypted during transmission, preventing eavesdropping and tampering. This section outlines how to configure TLS for secure event forwarding between Windows servers.
Prerequisites¶
Before configuring TLS, ensure: - The collector is configured to accept secure connections (HTTPS). - A valid TLS certificate is installed on the collector. - The source server trusts the collector’s certificate (added to the Trusted Root Certification Authorities store).
Step 1: Prepare the Collector for TLS¶
- Install a TLS certificate on the collector:
- Use a trusted Certificate Authority (CA) or self-signed certificate.
-
Install the certificate in the Local Computer store, ensuring it is marked as Trusted Root Certification Authorities.
-
Configure the collector to use HTTPS:
- If using a remote collector (e.g., a server running the Event Collector service), ensure it listens on port
5986(WinRM over HTTPS). - Verify the collector’s firewall allows inbound traffic on port
5986.
Step 2: Configure the Source to Trust the Collector’s Certificate¶
-
Import the collector’s certificate into the source’s Trusted Root Certification Authorities store:
ReplaceImport-Certificate -FilePath "C:\path\to\collector-cert.cer" -CertStoreLocation Cert:\LocalMachine\Rootcollector-cert.cerwith the path to the collector’s certificate file. -
Verify the certificate is trusted:
Step 3: Create a Secure Event Subscription¶
- Create a subscription using PowerShell to enforce TLS:
-SecureConnectionenables TLS encryption.-
Replace
collector.example.comwith the collector’s hostname or IP address. -
Verify the subscription:
Step 4: Validate TLS Configuration¶
-
Test connectivity using
Ensure the connection is successful and the firewall allows traffic.Test-NetConnection: -
Check event logs on the source and collector for errors related to TLS handshake or certificate trust issues.
Step 5: Monitor and Audit¶
- Use Windows Event Viewer or Log Analytics to monitor forwarded events.
- Regularly audit certificates to ensure they are valid and not expired.
- Use Group Policy to enforce TLS settings across multiple sources.
Key takeaways¶
- TLS encryption is critical for securing event data in transit between sources and collectors.
- The collector must host a trusted certificate, and the source must trust it.
- PowerShell cmdlets like
New-EventLogSubscriptionandImport-Certificatesimplify TLS configuration. - Regularly validate certificate trust and firewall rules to maintain secure communication.