cancel
Showing results for 
Search instead for 
Did you mean: 
Create Post
Level 11

Forwarded Windows Events Not Showing in LogA

Jump to solution

I have a remote server that is forwarding windows events to our orion server event viewer but nothing from the event viewer is showing in LogA. We are trying to get actual Windows Events to show in LogA so we can create rules based off Event ID. Any ideas?

1 Solution
Product Manager
Product Manager

When you are forwarding events like that you need to have the Orion agent installed on the machine where the events are being forwarded to (the collector). Each of the machines which are forwarding their events to the collector must be monitored nodes in Orion (SNMP, WMI, Ping) so that the events received for them can be properly mapped to their Orion entity. It is possible to do this without the agent on the collector but doing so requires that you use our free tool to covert the Windows Events to syslog: https://www.solarwinds.com/free-tools/event-log-forwarder-for-windows

Full doc for the set up process is here:

https://documentation.solarwinds.com/en/Success_Center/LA/Content/LM/LM-Set-up-Windows-Event-Collect...

View solution in original post

1 Reply
Product Manager
Product Manager

When you are forwarding events like that you need to have the Orion agent installed on the machine where the events are being forwarded to (the collector). Each of the machines which are forwarding their events to the collector must be monitored nodes in Orion (SNMP, WMI, Ping) so that the events received for them can be properly mapped to their Orion entity. It is possible to do this without the agent on the collector but doing so requires that you use our free tool to covert the Windows Events to syslog: https://www.solarwinds.com/free-tools/event-log-forwarder-for-windows

Full doc for the set up process is here:

https://documentation.solarwinds.com/en/Success_Center/LA/Content/LM/LM-Set-up-Windows-Event-Collect...

View solution in original post