Skip to content

Drops Troubleshooting

Diagnosing and Resolving Event Drop Issues with Subscription Filters

When events fail to reach the centralized event log or SIEM system, subscription filters often act as the first point of failure. Misconfigured XPath queries, incorrect event ID ranges, or mismatched event sources can cause events to be silently dropped. This section outlines structured diagnostic steps and mitigation strategies to resolve such issues.


1. Validate Filter Syntax with Local Event Filtering

Begin by testing your XPath filter on the source server to confirm it matches expected events. Use PowerShell to simulate filtering locally:

Get-WinEvent -FilterXPath "Event[System[EventID=4625 and EventRecordID>1000]]" | Format-List
- If no results are returned, refine the query (e.g., remove EventRecordID>1000) or verify event IDs in the Event Viewer > Windows Logs > Security. - Ensure the XPath uses Event[System[...]] for system events or Event[...][System[...]] for combined criteria.


2. Check Event Logs on the Collector Server

The collector server may log dropped events in the Forwarded Events log. Look for: - Event ID 10003: Indicates events were dropped due to filter mismatches. - Event ID 10004: Events were dropped due to resource constraints (e.g., log size limits).

Get-WinEvent -FilterXPath "Event[System[EventID=10003]]" | Format-List
Review the Message field for details about the dropped event's properties.


3. Audit Subscription Configuration

Verify the subscription settings in Event Viewer > Forwarding Settings: - Confirm the Event Source matches the source server's name or IP. - Ensure the Subscription Name and Collector Name are correctly specified. - Check that the Event Log is set to Application, Security, or System (depending on your use case).


4. Test with a Minimal Filter

Simplify the filter to isolate issues. For example:

<QueryList>
  <Query Id="1" Path="Security">
    <Select>*</Select>
    <Condition>EventID=4625</Condition>
  </Query>
</QueryList>
If this works, gradually reintroduce complexity (e.g., EventRecordID>1000, TimeCreated > 2023-01-01T00:00:00).


5. Check Network and Firewall Rules

Ensure the source and collector can communicate on port 5986 (HTTPS for WinRM) and 5985 (HTTP). Use Test-NetConnection to verify connectivity:

Test-NetConnection -ComputerName <CollectorName> -Port 5986
Confirm that the source server's firewall allows outbound traffic to the collector on these ports.


6. Use the Event Forwarding Troubleshooter

Open Event Viewer > Tools > Event Forwarding Troubleshooter to automatically detect common configuration issues, such as: - Missing or invalid subscription configurations. - Incorrect source/collector server names.


Key takeaways

  • Test filters locally using PowerShell to validate XPath syntax and event criteria.
  • Monitor the Forwarded Events log on the collector for dropped events (e.g., Event ID 10003).
  • Simplify filters incrementally to isolate misconfigurations.
  • Verify network connectivity and firewall rules between source and collector.
  • Leverage built-in tools like the Event Forwarding Troubleshooter for automated diagnostics.