<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Event Forwarding (WEF) Subscription Issue in Workgroup Environment in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Event-Forwarding-WEF-Subscription-Issue-in-Workgroup/m-p/762512#M30042</link>
    <description>&lt;P class=""&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I'm building a lab to centralize Windows Event Logs before sending them to Splunk. The objective is to collect Windows event logs from multiple Windows servers at a single Windows Event Collector (WEC), then forward the centralized logs to Splunk using a Universal Forwarder.&lt;/P&gt;&lt;H2&gt;Lab Architecture&lt;BR /&gt;&lt;BR /&gt;&lt;/H2&gt;&lt;P&gt;AWS VPC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WINSRC01 (Windows Server 2022)&lt;BR /&gt;Event Source&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;WINSRC02 (Windows Server 2022)&lt;BR /&gt;Event Source&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;Windows Event Forwarding (WEF)&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;WEC01 (Windows Server 2022)&lt;BR /&gt;Windows Event Collector (WEC)&lt;BR /&gt;+ Splunk Universal Forwarder&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;Splunk Heavy Forwarder (RedHat)&lt;BR /&gt;Splunk Enterprise 9.4.1&lt;/P&gt;&lt;H3&gt;Objective&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;WINSRC01 and WINSRC02 should forward their Windows Event Logs (Application, Security, and System) to WEC01 using Windows Event Forwarding (WEF).&lt;/LI&gt;&lt;LI&gt;WEC01 should collect all forwarded events in the &lt;STRONG&gt;Forwarded Events log.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;A Splunk Universal Forwarder installed on WEC01 should monitor the &lt;STRONG&gt;&lt;STRONG&gt;Forwarded Events log and forward the data to a Splunk Heavy Forwarder running on Redhat.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;P&gt;This design reduces the number of Splunk forwarders and provides a centralized Windows event collection point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Configuration Performed&lt;/H1&gt;&lt;UL&gt;&lt;LI&gt;Deployed three Windows Server 2022 EC2 instances in the same AWS VPC.&lt;/LI&gt;&lt;LI&gt;Configured one server as the Windows Event Collector (WEC01).&lt;/LI&gt;&lt;LI&gt;Configured the other two servers as event source computers.&lt;/LI&gt;&lt;LI&gt;Enabled WinRM and PowerShell remoting on all servers.&lt;/LI&gt;&lt;LI&gt;Successfully initialized the Windows Event Collector using:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Powershell&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;wecutil &lt;SPAN class=""&gt;qc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;UL&gt;&lt;LI&gt;Verified WinRM connectivity between the collector and both source servers using Test-WSMan.&lt;/LI&gt;&lt;LI&gt;Confirmed TCP port 5985 is reachable.&lt;/LI&gt;&lt;LI&gt;Configured Windows Firewall appropriately.&lt;HR /&gt;&lt;H1&gt;Problem Faced&lt;/H1&gt;&lt;P&gt;Since the servers are standalone workgroup machines (not joined to Active Directory), we encountered multiple issues while configuring Windows Event Forwarding.&lt;/P&gt;&lt;P&gt;1. Collector-Initiated Subscription&lt;/P&gt;&lt;P&gt;When creating a Collector-Initiated subscription, clicking Select Computers failed because the dialog searches Active Directory for computer objects. Since our servers are not domain joined, Windows could not locate WINSRC01 or WINSRC02.&lt;/P&gt;&lt;P&gt;2. Source-Initiated Subscription&lt;/P&gt;&lt;P&gt;We then switched to a Source-Initiated subscription.&lt;/P&gt;&lt;P&gt;The Event Viewer GUI would not allow us to save the subscription correctly, so we created it using:&lt;/P&gt;&lt;P&gt;wecutil cs WindowsServerLogs.xml&lt;/P&gt;&lt;P&gt;The subscription was created successfully, but it never became active.&lt;/P&gt;&lt;P&gt;Running:&lt;BR /&gt;cmd&lt;BR /&gt;wecutil gr WindowsServerLogs&lt;/P&gt;&lt;P&gt;returned:&lt;/P&gt;&lt;P&gt;RunTimeStatus : Inactive&lt;BR /&gt;LastError : 1337&lt;BR /&gt;ErrorMessage : The security ID structure is invalid.&lt;/P&gt;&lt;P&gt;The subscription creation command also reported:&lt;/P&gt;&lt;P&gt;The subscription is saved successfully,&lt;BR /&gt;but it can't be activated at this time.&lt;/P&gt;&lt;P&gt;Error = 0x3ae8&lt;BR /&gt;The subscription fails to activate.&lt;BR /&gt;Additional Observation&lt;/P&gt;&lt;P&gt;Running:&lt;/P&gt;&lt;P&gt;cmd&lt;/P&gt;&lt;P&gt;wecutil gs WindowsServerLogs&lt;/P&gt;&lt;P&gt;shows:&lt;/P&gt;&lt;P&gt;AllowedSourceDomainComputers:&lt;BR /&gt;O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS)&lt;/P&gt;&lt;P&gt;which appears to be a security descriptor intended for domain computers, even though our environment consists entirely of workgroup servers.&lt;/P&gt;&lt;P&gt;Question&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented Windows Event Forwarding in a standalone workgroup environment using the architecture shown above?&lt;/P&gt;&lt;P&gt;Specifically:&lt;/P&gt;&lt;P&gt;Is Source-Initiated WEF over HTTP supported without Active Directory?&lt;BR /&gt;Does the LastError: 1337 (The security ID structure is invalid) indicate that the collector is expecting domain-based security identifiers?&lt;BR /&gt;Is HTTPS with certificates required for workgroup-based Source-Initiated subscriptions?&lt;BR /&gt;Would it be better to deploy Active Directory and use Kerberos authentication for this architecture?&lt;/P&gt;&lt;P&gt;Any guidance or working examples would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 27 Jul 2026 11:56:01 GMT</pubDate>
    <dc:creator>_Raj</dc:creator>
    <dc:date>2026-07-27T11:56:01Z</dc:date>
    <item>
      <title>Windows Event Forwarding (WEF) Subscription Issue in Workgroup Environment</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Event-Forwarding-WEF-Subscription-Issue-in-Workgroup/m-p/762512#M30042</link>
      <description>&lt;P class=""&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I'm building a lab to centralize Windows Event Logs before sending them to Splunk. The objective is to collect Windows event logs from multiple Windows servers at a single Windows Event Collector (WEC), then forward the centralized logs to Splunk using a Universal Forwarder.&lt;/P&gt;&lt;H2&gt;Lab Architecture&lt;BR /&gt;&lt;BR /&gt;&lt;/H2&gt;&lt;P&gt;AWS VPC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WINSRC01 (Windows Server 2022)&lt;BR /&gt;Event Source&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;WINSRC02 (Windows Server 2022)&lt;BR /&gt;Event Source&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;Windows Event Forwarding (WEF)&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;WEC01 (Windows Server 2022)&lt;BR /&gt;Windows Event Collector (WEC)&lt;BR /&gt;+ Splunk Universal Forwarder&lt;BR /&gt;│&lt;BR /&gt;│&lt;BR /&gt;▼&lt;BR /&gt;Splunk Heavy Forwarder (RedHat)&lt;BR /&gt;Splunk Enterprise 9.4.1&lt;/P&gt;&lt;H3&gt;Objective&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;WINSRC01 and WINSRC02 should forward their Windows Event Logs (Application, Security, and System) to WEC01 using Windows Event Forwarding (WEF).&lt;/LI&gt;&lt;LI&gt;WEC01 should collect all forwarded events in the &lt;STRONG&gt;Forwarded Events log.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;A Splunk Universal Forwarder installed on WEC01 should monitor the &lt;STRONG&gt;&lt;STRONG&gt;Forwarded Events log and forward the data to a Splunk Heavy Forwarder running on Redhat.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;P&gt;This design reduces the number of Splunk forwarders and provides a centralized Windows event collection point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Configuration Performed&lt;/H1&gt;&lt;UL&gt;&lt;LI&gt;Deployed three Windows Server 2022 EC2 instances in the same AWS VPC.&lt;/LI&gt;&lt;LI&gt;Configured one server as the Windows Event Collector (WEC01).&lt;/LI&gt;&lt;LI&gt;Configured the other two servers as event source computers.&lt;/LI&gt;&lt;LI&gt;Enabled WinRM and PowerShell remoting on all servers.&lt;/LI&gt;&lt;LI&gt;Successfully initialized the Windows Event Collector using:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Powershell&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;wecutil &lt;SPAN class=""&gt;qc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;UL&gt;&lt;LI&gt;Verified WinRM connectivity between the collector and both source servers using Test-WSMan.&lt;/LI&gt;&lt;LI&gt;Confirmed TCP port 5985 is reachable.&lt;/LI&gt;&lt;LI&gt;Configured Windows Firewall appropriately.&lt;HR /&gt;&lt;H1&gt;Problem Faced&lt;/H1&gt;&lt;P&gt;Since the servers are standalone workgroup machines (not joined to Active Directory), we encountered multiple issues while configuring Windows Event Forwarding.&lt;/P&gt;&lt;P&gt;1. Collector-Initiated Subscription&lt;/P&gt;&lt;P&gt;When creating a Collector-Initiated subscription, clicking Select Computers failed because the dialog searches Active Directory for computer objects. Since our servers are not domain joined, Windows could not locate WINSRC01 or WINSRC02.&lt;/P&gt;&lt;P&gt;2. Source-Initiated Subscription&lt;/P&gt;&lt;P&gt;We then switched to a Source-Initiated subscription.&lt;/P&gt;&lt;P&gt;The Event Viewer GUI would not allow us to save the subscription correctly, so we created it using:&lt;/P&gt;&lt;P&gt;wecutil cs WindowsServerLogs.xml&lt;/P&gt;&lt;P&gt;The subscription was created successfully, but it never became active.&lt;/P&gt;&lt;P&gt;Running:&lt;BR /&gt;cmd&lt;BR /&gt;wecutil gr WindowsServerLogs&lt;/P&gt;&lt;P&gt;returned:&lt;/P&gt;&lt;P&gt;RunTimeStatus : Inactive&lt;BR /&gt;LastError : 1337&lt;BR /&gt;ErrorMessage : The security ID structure is invalid.&lt;/P&gt;&lt;P&gt;The subscription creation command also reported:&lt;/P&gt;&lt;P&gt;The subscription is saved successfully,&lt;BR /&gt;but it can't be activated at this time.&lt;/P&gt;&lt;P&gt;Error = 0x3ae8&lt;BR /&gt;The subscription fails to activate.&lt;BR /&gt;Additional Observation&lt;/P&gt;&lt;P&gt;Running:&lt;/P&gt;&lt;P&gt;cmd&lt;/P&gt;&lt;P&gt;wecutil gs WindowsServerLogs&lt;/P&gt;&lt;P&gt;shows:&lt;/P&gt;&lt;P&gt;AllowedSourceDomainComputers:&lt;BR /&gt;O:NSG:NSD:(A;;GA;;;DC)(A;;GA;;;NS)&lt;/P&gt;&lt;P&gt;which appears to be a security descriptor intended for domain computers, even though our environment consists entirely of workgroup servers.&lt;/P&gt;&lt;P&gt;Question&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented Windows Event Forwarding in a standalone workgroup environment using the architecture shown above?&lt;/P&gt;&lt;P&gt;Specifically:&lt;/P&gt;&lt;P&gt;Is Source-Initiated WEF over HTTP supported without Active Directory?&lt;BR /&gt;Does the LastError: 1337 (The security ID structure is invalid) indicate that the collector is expecting domain-based security identifiers?&lt;BR /&gt;Is HTTPS with certificates required for workgroup-based Source-Initiated subscriptions?&lt;BR /&gt;Would it be better to deploy Active Directory and use Kerberos authentication for this architecture?&lt;/P&gt;&lt;P&gt;Any guidance or working examples would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 27 Jul 2026 11:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Windows-Event-Forwarding-WEF-Subscription-Issue-in-Workgroup/m-p/762512#M30042</guid>
      <dc:creator>_Raj</dc:creator>
      <dc:date>2026-07-27T11:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Forwarding (WEF) Subscription Issue in Workgroup Environment</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Windows-Event-Forwarding-WEF-Subscription-Issue-in-Workgroup/m-p/762513#M30043</link>
      <description>&lt;P&gt;I haven't worked with it for quite a while (I had a non-AD WEF setup some 5+ years ago) but I seem to recall that without AD WEF worked only in one mode (apparently it is pull only).&lt;/P&gt;&lt;P&gt;And it required an insane amount of work to establish the trust relation between the source and the collector (AFAIR it was all based on cert-based authentication and there was no way around it).&lt;/P&gt;&lt;P&gt;So you'd be much better of with just installing the UF on the source machines if you have that possibility.&lt;/P&gt;&lt;P&gt;BTW, if you do have AD environment WEF is a very easy thing to set up.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 12:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Windows-Event-Forwarding-WEF-Subscription-Issue-in-Workgroup/m-p/762513#M30043</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-27T12:20:32Z</dc:date>
    </item>
  </channel>
</rss>

