WEF (Windows Event Forwarding)

Description

A native Windows service that forwards Windows events to a WEC (Windows Event Collector). It is used for Agentless log collection, when installing a log collection agent is not possible, for example, due to operational or compliance requirements.

While WEF is a valuable technology, it has its limitations. Some of these limitations include being unable to forward logs from Event Tracing Providers, scaling and managing many WEF clients being difficult, and not being able to forward events directly to a SIEM.

NXLog Agent supports collecting Windows events from WEF clients, either by taking the role of a WEC server or by collecting forwarded events from a Windows WEC server.

Also known as

Windows event log forwarding, Windows WEF, WEF Windows, Windows log forwarding

See also

Collect logs from Windows Event Forwarding

R

X