cancel
Showing results for 
Search instead for 
Did you mean: 
Create Post
Level 11

Forwarded Windows Events Not Showing in LogA

Jump to solution

I have a remote server that is forwarding windows events to our orion server event viewer but nothing from the event viewer is showing in LogA. We are trying to get actual Windows Events to show in LogA so we can create rules based off Event ID. Any ideas?

1 Solution
Product Manager
Product Manager

When you are forwarding events like that you need to have the Orion agent installed on the machine where the events are being forwarded to (the collector). Each of the machines which are forwarding their events to the collector must be monitored nodes in Orion (SNMP, WMI, Ping) so that the events received for them can be properly mapped to their Orion entity. It is possible to do this without the agent on the collector but doing so requires that you use our free tool to covert the Windows Events to syslog: https://www.solarwinds.com/free-tools/event-log-forwarder-for-windows

Full doc for the set up process is here:

https://documentation.solarwinds.com/en/Success_Center/LA/Content/LM/LM-Set-up-Windows-Event-Collect...

View solution in original post

4 Replies
Product Manager
Product Manager

When you are forwarding events like that you need to have the Orion agent installed on the machine where the events are being forwarded to (the collector). Each of the machines which are forwarding their events to the collector must be monitored nodes in Orion (SNMP, WMI, Ping) so that the events received for them can be properly mapped to their Orion entity. It is possible to do this without the agent on the collector but doing so requires that you use our free tool to covert the Windows Events to syslog: https://www.solarwinds.com/free-tools/event-log-forwarder-for-windows

Full doc for the set up process is here:

https://documentation.solarwinds.com/en/Success_Center/LA/Content/LM/LM-Set-up-Windows-Event-Collect...

View solution in original post

@jvb  , We are looking for option to forward Windows events on Windows 2019 server to OLV,

 We are planning to achieve through Windows Event log forwarder , But 'windows 2019' is not mentioned in supported OS in documents. Could you please help with further directions on this

 

FYI: I have Solarwinds Agent on the Server , But i dont have LA license for them, OLV alone is available

0 Kudos

The Windows event forwarder is actually built by another team and not the LA team. I am checking with that other team to see if we can get that updated to reflect support for 2019.

@jvb , Thanks for listening to our concern, We validate the windows event forwarder in Windows 2019, it is working fine as expected.

We looking forward to see the changes in official documentations too.

0 Kudos