Security Log Event Forwarding

Discussion in 'Windows Server' started by Tim Chin, Apr 29, 2010.

  1. Tim Chin

    Tim Chin Guest

    Has anyone had success forwarding events from the Security log? I was able
    to get the Application & System logs working as expected using the machine
    account, but nothing from the Security log will work. I'm trying to pull DS
    Access Changes events from all Domain Controllers running Server 2008 R2 in
    a single forest AD domain to a Server 2008 R2 member server. I've also
    tried running the subscription as a Domain Admin for testing, but I receive
    the same error:

    Code (0x138C): <f:providerFault provider="Event Forwarding Plugin"
    path="%systemroot%\system32\wevtfwd.dll"
    xmlns:f="http://schemas.microsoft.com/wbem/wsman/1/wsmanfault"><t:providerError
    xmlns:t="http://schemas.microsoft.com/wbem/wsman/1/windows/EventLog">Windows
    Event Forward plugin can't read any event from the query since the query
    returns no active channel. Please check channels in the query and make sure
    they exist and you have access to them.</t:providerError></f:providerFault>

    Any help is appreciated. Thank you.
    Tim
     
    Tim Chin, Apr 29, 2010
    #1
    1. Advertisements

  2. Tim Chin

    Tim Chin Guest

    I was actually able to get this going by restarting the source computers.
    Apparently, this step is necessary after adding NETWORK SERVICE to the
    builtin Event Log Readers group.

    Tim
     
    Tim Chin, May 2, 2010
    #2
    1. Advertisements

  3. Tim Chin

    Vitaly K Guest

    Sorry, but tt does not help

     
    Vitaly K, Jan 17, 2011
    #3
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.