Skip to content

Enabling WinRM

Windows Event Forwarding relies on WinRM (Windows Remote Management) to securely transmit event logs from source servers to a centralized event collector. Enabling WinRM correctly ensures reliable and secure communication. This section outlines the steps to configure WinRM for event forwarding.


Enabling the WinRM Service

The WinRM service must be running and configured to accept remote connections.

  1. Start and set the service to automatic:

    Start-Service WinRM
    Set-Service -Name WinRM -StartupType Automatic
    
    Verify the service status:
    Get-Service -Name WinRM
    

  2. Configure WinRM settings:
    Use Set-WSManQuickConfig for a basic setup (HTTP/HTTPS):

    Set-WSManQuickConfig -Force
    
    This enables HTTP (port 5985) and HTTPS (port 5,986) listeners. For HTTPS, ensure a valid certificate is installed (see next section).


Configuring WinRM Listeners

For secure event forwarding, configure WinRM to use HTTPS with a trusted certificate.

  1. Create a self-signed certificate (for testing):

    New-SelfSignedCertificate -DnsName "localhost" -CertStoreLocation "cert:\LocalMachine\My"
    
    Replace "localhost" with your server’s FQDN if needed.

  2. Register the certificate with WinRM:

    $cert = Get-ChildItem -Path "cert:\LocalMachine\My" | Where-Object { $_.Subject -like "*your-dns-name*" }
    Register-WSManInstance -Listener "https" -CertificateThumbprint $cert.Thumbprint
    

  3. Verify listener configuration:

    Get-WSManSetting | Select-Object -ExpandProperty TrustedHosts
    
    Ensure the collector server’s IP/FQDN is added to trusted hosts if required.


Firewall Configuration

Allow WinRM traffic through the firewall.

  1. Check existing rules:

    Get-NetFirewallRule -Name *winrm*
    

  2. Add rules for HTTP/HTTPS (if missing):

    New-NetFirewallRule -Name "WinRM-HTTP" -DisplayName "WinRM HTTP" -Direction Inbound -Protocol TCP -LocalPort 5985 -Action Allow
    New-NetFirewallRule -Name "WinRM-HTTPS" -DisplayName "WinRM HTTPS" -Direction Inbound -Protocol TCP -LocalPort 5986 -Action Allow
    

  3. Ensure the firewall is not blocking traffic:

    Get-NetFirewallProfile | Select-Object -ExpandProperty Enabled
    
    Disable "Block all incoming connections" if necessary.


Testing WinRM Connectivity

Verify the configuration with:

Test-WSMan -ComputerName localhost
A successful test confirms WinRM is operational. Check event logs (Event ID 6008) for errors if issues occur.


Security Best Practices

  • Use HTTPS: Always enable HTTPS with a trusted certificate (avoid self-signed certs in production).
  • Restrict access: Limit WinRM to trusted IPs or networks using firewall rules.
  • Audit logs: Monitor event logs for unauthorized access attempts (Event ID 4104).

Key takeaways

  • WinRM must be enabled and configured for HTTPS to secure event forwarding.
  • Firewall rules for ports 5985 (HTTP) and 5986 (HTTPS) are critical.
  • Use trusted certificates and restrict access to prevent unauthorized connections.
  • Regularly test connectivity and audit logs for security compliance.