Collector Testing
After setting up the event forwarding collector, it's critical to validate its connectivity and ensure logs are being collected as expected. This section outlines steps to generate test events, verify collector logs, and troubleshoot common issues.
Generating Test Events on Source Servers¶
To confirm the collector is receiving events, generate test events on a source server and verify they appear in the collector.
-
Create a test event using PowerShell:
Run the following command on a source server to generate a custom event:
This creates an event with ID$event = New-Object System.Diagnostics.Eventing.EventSource("TestEventSource") $event.WriteEvent(1, "Test event message", @("Test event data"))1and a custom message. -
Verify the event is forwarded:
If the event is not visible, check firewall rules, subscription configurations, or DNS resolution (if the collector is remote).
On the collector, useGet-WinEventto check if the event appears:
Verifying Collector Logs¶
The collector logs provide insights into event forwarding status and errors.
- Access the collector's Event Viewer:
- Open Event Viewer (
eventvwr.exe). -
Navigate to Applications and Services Logs > Microsoft-Windows-EventForwarding/Operational.
-
Check for key event IDs:
- Event ID 10001: Indicates an event was received by the collector.
- Event ID 10002: Indicates an event was not forwarded (e.g., due to subscription issues).
- Event ID 10003: Indicates an event was dropped due to storage limits.
- Event ID 10004: Indicates an event was successfully forwarded.
Example query to filter for success/failure:
Get-WinEvent -LogName Microsoft-Windows-EventForwarding/Operational | Where-Object { $_.Id -in 10001, 10002, 10004 }
Troubleshooting Connectivity Issues¶
If events are not appearing in the collector:
1. Check firewall rules: Ensure port 5959 (Event Forwarding) is allowed between source and collector.
2. Validate subscriptions: Confirm the collector's subscription settings are correctly configured in Group Policy or the Event Forwarding Configuration tool.
3. Test DNS resolution: If the collector is remote, ensure the source can resolve the collector’s hostname.
4. Review collector logs: Look for errors related to failed connections or malformed subscriptions.
Key takeaways¶
- Generate test events on source servers to validate collector reception.
- Monitor the collector’s Microsoft-Windows-EventForwarding/Operational log for event IDs like 10001 (success) and 10002 (failure).
- Use
Get-WinEventto filter and analyze log entries for troubleshooting. - Ensure firewall rules, DNS, and subscription configurations are correct for reliable connectivity.
- Regularly review logs to identify dropped events or configuration errors.