{"id":20156276,"url":"https://github.com/dsccommunity/xwindowseventforwarding","last_synced_at":"2025-04-09T22:23:25.608Z","repository":{"id":30741896,"uuid":"34298309","full_name":"dsccommunity/xWindowsEventForwarding","owner":"dsccommunity","description":"DSC Module to manage Windows Event Forwarding","archived":false,"fork":false,"pushed_at":"2018-09-22T14:55:51.000Z","size":54,"stargazers_count":23,"open_issues_count":9,"forks_count":13,"subscribers_count":17,"default_branch":"dev","last_synced_at":"2025-03-24T00:16:50.606Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"lirantal/Riess.js","license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dsccommunity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-04-21T02:08:50.000Z","updated_at":"2024-09-01T23:10:18.000Z","dependencies_parsed_at":"2022-08-26T12:11:46.198Z","dependency_job_id":null,"html_url":"https://github.com/dsccommunity/xWindowsEventForwarding","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dsccommunity%2FxWindowsEventForwarding","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dsccommunity%2FxWindowsEventForwarding/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dsccommunity%2FxWindowsEventForwarding/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dsccommunity%2FxWindowsEventForwarding/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dsccommunity","download_url":"https://codeload.github.com/dsccommunity/xWindowsEventForwarding/tar.gz/refs/heads/dev","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248120900,"owners_count":21051043,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-13T23:38:15.558Z","updated_at":"2025-04-09T22:23:25.585Z","avatar_url":"https://github.com/dsccommunity.png","language":"PowerShell","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![Build status](https://ci.appveyor.com/api/projects/status/8ds3u9f79v2cwx54/branch/master?svg=true)](https://ci.appveyor.com/project/PowerShell/xwindowseventforwarding/branch/master)\r\n\r\n# xWindowsEventForwarding\r\n\r\nThe **xWindowsEventForwarding** module is a part of the Windows PowerShell Desired State Configuration (DSC) Resource Kit, which is a collection of DSC Resources. This module contains the **xWEFCollector and xWEFSubscription** resources. These resources enable you to configure a server to become an Event Collector role and create complex Subscriptions, with simple declarative language.\r\n\r\n**All of the resources in the DSC Resource Kit are provided AS IS, and are not supported through any Microsoft standard support program or service. The \"x\" in xWindowsEventForwarding stands for experimental**, which means that these resources will be **fix forward** and monitored by the module owner(s).\r\n\r\nPlease leave comments, feature requests, and bug reports in the Q \u0026 A tab for\r\nthis module.\r\n\r\nIf you would like to modify the **xWindowsEventForwarding** module, feel free. When modifying, please update the module name, resource friendly name, and MOF class name (instructions below). As specified in the license, you may copy or modify this resource as long as they are used on the Windows Platform.\r\n\r\nFor more information about Windows PowerShell Desired State Configuration, check out the blog posts on the [PowerShell Blog](http://blogs.msdn.com/b/powershell/) ([this](http://blogs.msdn.com/b/powershell/archive/2013/11/01/configuration-in-a-devops-world-windows-powershell-desired-state-configuration.aspx) is a good starting point). There are also great community resources, such as [PowerShell.org](http://powershell.org/wp/tag/dsc/), or [PowerShell Magazine](http://www.powershellmagazine.com/tag/dsc/). For more information on the DSC Resource Kit, checkout [this blog post](http://go.microsoft.com/fwlink/?LinkID=389546).\r\n\r\n## Installation\r\n\r\nTo install **xWindowsEventForwarding** module\r\n\r\n- If you are using WMF4 / PowerShell Version 4: Unzip the content under $env:ProgramFilesWindowsPowerShellModules folder\r\n- If you are using WMF5 Preview: From an elevated PowerShell session run �Install-Module xWindowsEventForwarding�\r\n\r\nTo confirm installation\r\n\r\n- Run Get-DSCResource to see that the resources listed above are among the DSC Resources displayed\r\n\r\n## Requirements\r\n\r\nThis module requires the latest version of PowerShell (v4.0, which ships in\r\nWindows 8.1 or Windows Server 2012R2). To easily use PowerShell 4.0 on older\r\noperating systems, install WMF 4.0. Please read the installation instructions\r\nthat are present on both the download page and the release notes for WMF 4.0.\r\n\r\n## Details\r\n\r\n**xWEFCollector** resource has following properties\r\n\r\n- **Ensure**: Determines whether the Collector service should be enabled or disabled\r\n- **Name**: Provide a unique name for the setting\r\n\r\n**xWEFSubscription** resource has the following properties\r\n\r\n- **SubscriptionID**: Name of the Subscription\r\n- **Ensure**: Determines whether to validate or remove the scubscription\r\n- **SubscriptionType**: Type of Subscription to create\r\n- **Description**: Description of the Collector subscription\r\n- **Enabled**: Sets whether the subscription will be enabled, default true\r\n- **DeliveryMode**: Configures whether the collector will pull events from source nodes or if the source nodes will push events to the collector, default push\r\n- **MaxItems**: The number of events that can occur on the source before they are submitted to the collector, default 1\r\n- **MaxLatencyTime**: The maximum amount of time that can pass before events are submitted to the collector, default 20000\r\n- **HeartBeatInterval**: Frequency to verify connectivity, default 20000\r\n- **ReadExistingEvents**: Should the collector read existing or only new events, default false\r\n- **TransportName**: Determines whether to require SSL, default HTTP\r\n- **TransportPort**: Set the port number that WinRM should use to make a connection, default 5985\r\n- **ContentFormat**: Format that event logs will be submitted in, default RenderedText\r\n- **Locale**: Sets the subscription Locale, default en-US\r\n- **LogFile**: Sets the event log that the collected events will be written to, default ForwardedEvents\r\n- **CredentialsType**: Sets the credential type used for authenticating to WinRM, default Default\r\n- **AllowedSourceNonDomainComputers**: This parameter has not been fully implemented, only required for source initiated scenarios, provide XML to set IssuerCAList, AllowedSubjectList, or DeniedSubjectList if this will be used, default empty string\r\n- **AllowedSourceDomainComputers**: In Source Initiated scenario this SDDL determines who can push events, default O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS) which equates to Domain Computers and Network Service\r\n- **Query**: Expects an array of hashtables that set which events should be collected, default is all application and system logs\r\n- **Address**: Expects an array of source node FQDNs, default source.wef.test to prevent errors when only staging test subscription\r\n\r\n## Scenario\r\n\r\nWindows Event Forwarding can be used in either a Collector Initiated or Source Initiated configuration.  Depending on the configuration there are unique combinations of parameters that should be used.  Before using this resource, it would be good understand the details of [WECUtil.exe](https://msdn.microsoft.com/en-us/library/windows/desktop/bb736545(v=vs.85).aspx).  That is the basis for the resource.\r\n\r\nThere is also [an article on MSDN](https://msdn.microsoft.com/en-us/library/windows/desktop/bb427443(v=vs.85).aspx) that provides a high level understanding of how Windows Event Forwarding should be configured.\r\n\r\nIn addition, For Windows Event Collection to function there are requirements that must be met on the Collector as well as on the servers that act as the Source of forwarded events.  In a Collector Initiated configuration, the only required change to the source machines will be to add the Collector machine domain account to the local **Event Log Readers** group.  In a Source Initiated configuration, DSC must be used in combination with Group Policy to configure the source machines with the Collector address before events will be forwarded.\r\n\r\nThis project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/).\r\nFor more information see the [Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/) or contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with any additional questions or comments.\r\n\r\n### Event Queries\r\n\r\nIn order to simplify querying for specific event logs, the following pattern is used.\r\n\r\n\"Log:Query\"\r\n\r\nSo to query the application log for all events, the query would be \"Application:*\".  The easiest way to identify the proper syntax for the right side of the colon delimiter is to use Windows Event Log and begin to create a new subscription, then view the XML representation of the query (copy and paste).\r\n\r\nFor multiple queries, comma separate multiple strings in an array.\r\n\r\n@('Application:*','System:*[System[(EventID=99)]]')\r\n\r\n### List of Source Machines\r\n\r\nIn a Collector Initiated scenario, a list of source machines must be provided.  The Address parameter fulfills this requirement.  When more than one machine is to be listed, provide an array of FQDNs.\r\n\r\n@('system1.domain.com', 'system2.domain.com')\r\n\r\n## Renaming Requirements\r\n\r\nWhen making changes to these resources, we suggest the following practice\r\n\r\n1. Update the following names by replacing MSFT with your company/community name\r\nand replacing the **\"x\" with **\"c\" (short for \"Community\") or another prefix of your\r\nchoice\r\n   - Module name (ex: xModule becomes cModule)\r\n   - Resource folder (ex: MSFT\\_xResource becomes Contoso\\_xResource)\r\n   - Resource Name (ex: MSFT\\_xResource becomes Contoso\\_cResource)\r\n   - Resource Friendly Name (ex: xResource becomes cResource)\r\n   - MOF class name (ex: MSFT\\_xResource becomes Contoso\\_cResource)\r\n   - Filename for the \u003cresource\\\u003e.schema.mof (ex: MSFT\\_xResource.schema.mof becomes Contoso\\_cResource.schema.mof)\r\n\r\n2. Update module and metadata information in the module manifest\r\n3. Update any configuration that use these resources\r\n\r\nWe reserve resource and module names without prefixes (\"x\" or \"c\") for future use (e.g. \"MSFT_Resource\"). If the next version of Windows Server ships with a \"WindowsEventForwarding\" resource, we don't want to break any configurations that use any community modifications. Please keep a prefix such as \"c\" on all community modifications.\r\n\r\n## Versions\r\n\r\n### Unreleased\r\n\r\n- Update appveyor.yml to use the default template.\r\n- Activated the GitHub App Stale on the GitHub repository\r\n- Resolved lint errors.\r\n- Added unit test template to folder Tests\\Unit.\r\n- Added default template files .codecov.yml, .gitattributes, and .gitignore, and\r\n  .vscode folder.\r\n- Cleanup in README.md.\r\n\r\n### 1.0.0.0\r\n\r\n- Initial release of xWindowsEventForwarding module with following modules:\r\n  - xWEFCollector\r\n  - xWEFSubscription\r\n\r\n## Examples\r\n\r\n**Example 1**:  Enable Collector role and a subscription that includes all Application\r\nand System logs from server tester.contoso.com.\r\n\r\n```powershell\r\nconfiguration SetupCollector\r\n{\r\n    Import-DscResource -ModuleName xWindowsEventForwarding\r\n    xWEFCollector Enabled\r\n    {\r\n        Ensure = \"Present\"\r\n        Name = \"Enabled\"\r\n    }\r\n    xWEFSubscription TestSub\r\n    {\r\n        SubscriptionID = \"TestSub\"\r\n        Ensure = \"Present\"\r\n        SubscriptionType = 'CollectorInitiated'\r\n        Address = 'tester.contoso.com'\r\n        DependsOn = \"[xWEFCollector]Enabled\"\r\n    }\r\n}\r\nSetupCollector -out c:\\DSC\\ -force\r\nStart-DscConfiguration -Wait -Force -Path c:\\DSC\\ -Verbose\r\n\r\n# Note that this configuration will apply to the Collector node.  On Source\r\n# nodes the machine account of the Collector must be added to the local\r\n# group \"Event Log Readers\".\r\n```\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdsccommunity%2Fxwindowseventforwarding","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdsccommunity%2Fxwindowseventforwarding","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdsccommunity%2Fxwindowseventforwarding/lists"}