Skip to content

Stream Encryption

Windows Event Forwarding (WEF) relies on secure communication between event sources and collectors to protect sensitive data in transit. Enabling TLS (Transport Layer Security) encryption ensures that event data is encrypted during transmission, preventing eavesdropping and tampering. This section outlines how to configure TLS for secure event forwarding between Windows servers.


Prerequisites

Before configuring TLS, ensure: - The collector is configured to accept secure connections (HTTPS). - A valid TLS certificate is installed on the collector. - The source server trusts the collector’s certificate (added to the Trusted Root Certification Authorities store).


Step 1: Prepare the Collector for TLS

  1. Install a TLS certificate on the collector:
  2. Use a trusted Certificate Authority (CA) or self-signed certificate.
  3. Install the certificate in the Local Computer store, ensuring it is marked as Trusted Root Certification Authorities.

  4. Configure the collector to use HTTPS:

  5. If using a remote collector (e.g., a server running the Event Collector service), ensure it listens on port 5986 (WinRM over HTTPS).
  6. Verify the collector’s firewall allows inbound traffic on port 5986.

Step 2: Configure the Source to Trust the Collector’s Certificate

  1. Import the collector’s certificate into the source’s Trusted Root Certification Authorities store:

    Import-Certificate -FilePath "C:\path\to\collector-cert.cer" -CertStoreLocation Cert:\LocalMachine\Root
    
    Replace collector-cert.cer with the path to the collector’s certificate file.

  2. Verify the certificate is trusted:

    Get-ChildItem -Path Cert:\LocalMachine\Root | Where-Object { $_.Subject -like "*collector.example.com*" }
    


Step 3: Create a Secure Event Subscription

  1. Create a subscription using PowerShell to enforce TLS:
    New-EventLogSubscription -CollectorComputer "collector.example.com" `
                             -SubscriptionName "Secure-Event-Forwarding" `
                             -LogName "Security" `
                             -IncludeEventIdentifier 4624,4625 `
                             -SecureConnection
    
  2. -SecureConnection enables TLS encryption.
  3. Replace collector.example.com with the collector’s hostname or IP address.

  4. Verify the subscription:

    Get-EventLogSubscription | Where-Object { $_.SubscriptionName -eq "Secure-Event-Forwarding" }
    


Step 4: Validate TLS Configuration

  1. Test connectivity using Test-NetConnection:

    Test-NetConnection -ComputerName collector.example.com -Port 5986
    
    Ensure the connection is successful and the firewall allows traffic.

  2. Check event logs on the source and collector for errors related to TLS handshake or certificate trust issues.


Step 5: Monitor and Audit

  • Use Windows Event Viewer or Log Analytics to monitor forwarded events.
  • Regularly audit certificates to ensure they are valid and not expired.
  • Use Group Policy to enforce TLS settings across multiple sources.

Key takeaways

  • TLS encryption is critical for securing event data in transit between sources and collectors.
  • The collector must host a trusted certificate, and the source must trust it.
  • PowerShell cmdlets like New-EventLogSubscription and Import-Certificate simplify TLS configuration.
  • Regularly validate certificate trust and firewall rules to maintain secure communication.