Skip to content

Collector Configuration

Installing and Configuring the Event Collector

The Event Collector service is a critical component of Windows Event Forwarding, responsible for aggregating events from remote servers. To set up a collector, you must first install the Event Log Forwarding feature and configure its basic settings, such as listening ports and storage options.


1. Install the Event Log Forwarding Feature

Using Server Manager: 1. Open Server Manager. 2. Navigate to Add roles and features. 3. Select the target server and proceed to the Server Roles page. 4. Expand Windows Server and check Event Log Forwarding. 5. Complete the wizard to install the feature.

Using PowerShell:

Install-WindowsFeature -Name "Event-Log-Forwarding" -IncludeManagementTools

Note: This feature is available in Windows Server 2012 R2 and later. For older versions, use the "Event Log" role with custom settings.


2. Configure the Event Collector Service

Via Event Viewer: 1. Open Event Viewer (eventvwr.msc). 2. Navigate to Windows Logs > Forwarding Settings. 3. Right-click Forwarding Settings and select Properties. 4. Under the General tab: - Set the Port (default: 5920). - Specify the Maximum number of events to store (e.g., 1000). - Choose the Retention period (e.g., 7 days). 5. Click OK to save changes.

Via PowerShell:

# Set the collector's listening port
Set-EventLogForwarding -Port 5920

# Configure event storage settings
Set-EventLogForwarding -MaxEvents 1000 -RetentionDays 7

Important: Ensure the firewall allows inbound traffic on the configured port (e.g., 5920). Use netsh advfirewall firewall add rule name="EventCollector" dir=in action=allow protocol=TCP localport=5920.


3. Verify the Collector is Ready

Run the following command to confirm the collector is active:

Get-EventLogForwarding

Look for the Status field; it should indicate the collector is running.


Key takeaways

  • The Event Collector is installed via the Event Log Forwarding feature or PowerShell.
  • Configure the collector's port, storage limits, and retention policies to match your infrastructure needs.
  • Always verify firewall rules allow traffic on the designated port (e.g., 5920).
  • Use PowerShell for automation or advanced configuration, or the Event Viewer GUI for quick adjustments.