Log forwarding

Last published : Jun 12, 2026
InfoScale introduced log forwarding for Windows machines. Windows Event Forwarding (WEF) reads any operational or administrative event log on a device and forwards the events you choose to a Windows Event Collector (WEC) server.
You can enable log forwarding on Windows server machines.
To forward the logs from Windows Event Forwarding (WEF) system:
  1. Open PowerShell console on forwarder system.
  2. Type winrm quickconfig to see winrm is running correctly.
If it is not running correctly, type Y to start the service.
  1. Open Computer Management.
  2. Click Groups.
  3. Open Event Log Readers.
  4. For event forwarding to work correctly, use the system account of the computer that will be functioning as the event collector or the domain account that the collector will be running on.
  5. Click Add.
  6. Click Object Types.
  7. Select the Computer check box.
  8. Enter the event collector system name in the box and click Check Names. It will validate the name of the machine in the network.
  9. Click OK.
The collector server has access to read the event logs and to set up the subscription.
To set up the subscription on collector server:
  1. Log in to event collector server.
  2. Open Event Viewer.
  3. From the left panel, click Subscriptions.
  4. Right click Subscription and selectCreate Subscriptions.
  5. Give the subscription a unique name, for example: client1Events.
  6. In Destination Log list, selectForwarded Events.
  7. There are two options of Subscription type , collector initiated and source computer initiated.
    • Collector Initiated means that the collector system will reach out to server(s) to collect the forwarded events. Collector initiated would work well in scenarios where there are small manageable number of forwarding computers.
    • Source Computer Initiated means that the forwarding computers will contact the collector computer to forward the events. Source computer initiated would help lower the strain on the collector in scenarios where there are large number of forwarding computers since the forwarding computers would be initiating the event forwarding instead of the collector.
  8. Click appropriate option from subscription and click Select Computers.
  9. Click Add Domain Computers.
  10. Enter the name of the event forwarding system and click Check Names.
  11. Once the system name is validated, click Test to check the connection.
  12. After successful testing, click OK and then again clickOK.
  13. In Events to Collect, click** Select Events.**
  14. Choose the events according to your requirements.
  15. In Event Logs list, select the logs that are to be collected.
  16. To save the settings, click OK.
  17. In **Advanced **settings, go to account settings to access the remote logs. By default,Machine Account is selected.
  18. The Event Delivery Optimization option will specify the frequency of event delivery to the collector.
The normal option will get events every 15 minutes and does not utilize the bandwidth.
The Minimize bandwidth option will limit the frequency of network connections and uses a heartbeat interval of 6 hours.
The Minimize Latency option will ensure that events are delivered most frequently. Events will be delivered every 30 seconds in this case.
  1. Select the appropriate option based on your requirements and click OK.
  2. Forwarded events will start appearing under Windows Logs inForwarded Events.
Related information