Security Event logs - Forwarding from Windows XP to Windows 2016/2019

Prasanna N 21 Reputation points
2021-05-24T12:16:37.757+00:00

My Environment:
Windows XP - Client (Workgroup)
Windows Server 2016/2019 - Collector (Domain)

Managed to set up Collector Initiated subscription and successfully forwarding Application and System events. However, when selecting "Security" events to be forwarded, I see the following event in "Microsoft Windows Forwarding Operational logs" of the Client:

The subscription "Name" is created, but one or more channels in the query could not be read at this time.

From various readings understood, that the "user" used for this purpose should be added to the "Event Log Readers" group, but in Windows XP there is no such group. Or can add permission via SDDL in Registry for Security events, but then the CustomSD value is not supported in Windows XP as per https://learn.microsoft.com/en-us/windows/win32/eventlog/eventlog-key

So is it even possible to forward "security logs" from Windows XP?

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,534 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,732 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sunny Qi 10,886 Reputation points Microsoft Vendor
    2021-05-25T08:38:35.917+00:00

    Hi,

    Thanks for posting in Q&A platform.

    Please understand, since support for Windows XP has ended from April 8, 2014, we do not have such Windows XP machine to test in our environment.

    I think the user should be added to the group Event Log Readers from DC, here is an article for your reference:

    Privileges/permissions required for event log collection
    Please Note: Since the websites are not hosted by Microsoft, the links may change without notice. Microsoft does not guarantee the accuracy of this information.

    Best Regards,
    Sunny

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful