Тёмный

MCTS 70-680: Event forwarding source initiated subscriptions 

ITFreeTraining
Подписаться 216 тыс.
Просмотров 47 тыс.
50% 1

Check out / itfreetraining or itfreetraining.com for more of our always free training videos.
This video looks at forwarding events from one computer to another using source initiated subscription. Source initiated subscription is when the computer that has events to transfer determines when to transfer these events to the collecting computer. The previous video looked at collector initiated subscription, which is when the collecting computer contacts the forwarding computer at regular intervals to see if it has events that it needs to transfer.
Previous Video on event forwarding using collector initiated subscriptions • MCTS 70-680: Windows 7...
Demo configuring the forwarding computer 01:56
Demo configuring the collector 05:24
Configuring the collector computer
To configure the collector computer to receive events from the forwarding computer, run the following two commands:
WinRM QuickConfig
WECUtil QC
Answer y to all the questions. WinRM will configure the WinRM service and the firewall. WECUtil will configure the service that is used to collect events sent from the forwarder.
The next step is to configure a subscription on the collector computer. This is done inside the event viewer on the collector computer. Right click on subscriptions in the event viewer and select create subscription. Make sure that source computer initiated is selected. The rest of the options determine which events will be transferred from the forwarding computer. The subscription in this case acts like a filter determining which events to collect and which events to ignore.
Configuring the forwarding computer
Run the following command on the forwarding computer:
WinRm QuickConfig
Answer y to both questions. This will configure the service and also the firewall settings.
Group Policy
The forwarding computer needs to be configured with the address of the server to which the events are forwarded. This can be done with the following group policy setting:
Computer configuration-Administrative templates-Windows components-Event forwarding-Configure the server address, refresh interval, and issue certificate authority of a target subscription manager.
The syntax is as follows when using the default protocol HTTP and default port:
Server=HTTP://FQDN
Use the full URL when using HTTPS or different ports:
Server=HTTPS://FQDN:5986/wsman/SubscriptionManager/WEC
FQDN is the fully qualified domain name, for example, ITFreeTraining.com
WECUtil command line
WECutil supports a number of different command line options which are listed below.
WECUtil ES
Lists the subscriptions. The name of the subscription can be used in later commands.
WECUtil GS (Subscription name) /f:XML
This outputs the subscription configuration. If you want XML format add /f:XML. (Greater than sign) filename can also be added to direct the output to a file.
WECUtil CS (Filename)
This will create a new subscription using the configuration in the filename.

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 19   
@dhingraabhi
@dhingraabhi 9 лет назад
Thanks man, Your videos are always good, Keep up the good work.
@joaocoimbra1586
@joaocoimbra1586 5 лет назад
great explanation
@0m4n1
@0m4n1 10 лет назад
thank you very much .... it was very useful info..
@itfreetraining
@itfreetraining 10 лет назад
Thanks, glad we could help.
@chamkadar86
@chamkadar86 2 года назад
Can you please make a video on how to add workgroup computer in the WEC using certificates please?
@jaorezende
@jaorezende 11 лет назад
Muito boa explicação.
@leonardorussi7200
@leonardorussi7200 10 лет назад
what you say I think is correct, but why books an manuals say to run only "wecutil qc" on the collector?
@sydxtain9188
@sydxtain9188 10 лет назад
thanks for your response.I am working on my private lab ,which i set up by using oracle vm and practice computers are in a work group mode. .Yea in my network and sharing center there is an unidentified public network but its not connected and cant seem to modify it to private network
@itfreetraining
@itfreetraining 10 лет назад
Which operating system are you using? In Windows 8 you need to go to Network Connection Settings, select connections, select you connection and then switch off the option for find device content.
@sydxtain9188
@sydxtain9188 10 лет назад
Am using windows 7 ultimate.
@itfreetraining
@itfreetraining 10 лет назад
Syd Xtain If you go into Network and Sharing Centrer, are you able to select the profile under active networks and change it.
@renaudperozzo7552
@renaudperozzo7552 6 лет назад
Hi, how do you use WEF (source initiated) using HTTPS when both source and WEC are not in a domain?
@AliKhan-qq1nc
@AliKhan-qq1nc 8 лет назад
sir tmg training
@itfreetraining
@itfreetraining 8 лет назад
+Ali Khan Thank you.
@haukehasselberg496
@haukehasselberg496 8 лет назад
TMG is dead! :P
@puneethpenetrator
@puneethpenetrator 11 лет назад
If i configure source initaited settings .how can i differenciate different computer events in collector computer .will all events fall in same locations or they fall in different as per computers
Далее
MCTS 70-680: Windows 7 events forwarding
12:10
Просмотров 24 тыс.
Windows Event Forwarding at Scale
33:02
Просмотров 16 тыс.
🦊🔥
00:16
Просмотров 789 тыс.
MCTS 70-680: Bitlocker
12:00
Просмотров 81 тыс.
MCTS 70-680: Authentication and Authorization
13:33
Просмотров 43 тыс.
MCTS 70-680: Windows 7 Remote Assistance/Desktop
14:01
Просмотров 140 тыс.
Windows Event Forwarding and Event Collectors In-Depth
57:40
Microsoft Exchange Server 5.5 - Email like its 1998
24:06
MCTS 70-680: Certifcates in Windows 7
11:44
Просмотров 21 тыс.
MCTS 70-680: File and folder access
15:58
Просмотров 27 тыс.