logo

End-Point Log Consolidation with Windows Event Forwarder

ID: c41857c9-86f8-5ede-9194-d0e1f2604881

STIX ID: report--c41857c9-86f8-5ede-9194-d0e1f2604881

Feed Name: Black Hills Infosec Blog

Date Published: 2017-09-27

Date Updated: 2026-04-27

Author: BHIS

...
...

This post explains how to build a Windows-native log collection pipeline using Windows Event Forwarding (WEF), including configuring WinRM/WEC, GPOs for subscriptions and permissions, deploying Sysmon with a tuned configuration, enabling PowerShell module and script block logging (4103/4104), and selecting key Security and Kerberos events (e.g., 4624/4625/4769) for centralized analysis. It also covers forwarding consolidated logs to an ELK stack to create a lightweight DIY SIEM for detection and hunting without deploying additional endpoint agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.