Centralize Windows Events with Source-Initiated Forwarding
Windows Event Forwarding (WEF) can centralize selected Windows events without installing a separate forwarding agent. In a source-initiated subscription, the collector defines the subscription and domain clients learn the collector address through Group Policy.
Pilot with a small computer group and a low-volume log such as System warnings and errors before collecting security events broadly. Event volume, retention, access control, and bandwidth should be planned for the collector.
Step 1: Prepare the Collector
Enable Windows Event Collector and WinRM
CollectorOn the designated collector, open an elevated Command Prompt. Configure WinRM and the Event Collector service, then verify the collector service state. Keep the collector on a trusted management network and allow the required Windows Remote Management traffic only from approved domain devices.
winrm qc -qwecutil qc /qsc query wecsvc❯ View Expected Console Output
SERVICE_NAME: wecsvc STATE : 4 RUNNINGStep 2: Create a Low-Volume Source-Initiated Subscription
Filter the Events Before Forwarding Them
SubscriptionIn Event Viewer on the collector, open Subscriptions and create a subscription. Choose Source computer initiated, select a pilot computer group, and start with System warning and error events. This keeps the initial test bounded while validating policy and connectivity.

Figure 1: Event Viewer Subscription Properties dialog defining source computer initiated parameters, computer groups, and event severity filters.
Subscription type: Source computer initiatedDestination log: ForwardedEventsSource computer group: WEF-Pilot-ComputersSelected log: SystemEvent levels: Critical, Error, Warning❯ View Expected Console Output
Subscription created on the collector for the pilot computer group.Step 3: Point Pilot Clients to the Collector
Configure Subscription Manager in Group Policy
Group PolicyCreate or edit a computer GPO linked only to the pilot computers. Enable Computer Configuration > Policies > Administrative Templates > Windows Components > Event Forwarding > Configure target Subscription Manager. Enter the collector’s fully qualified domain name and use the documented WEC URL form.

Figure 2: GPO Configure target Subscription Manager setting pointing endpoints to the collector FQDN over port 5985.
Server=http://wec01.contoso.com:5985/wsman/SubscriptionManager/WEC,Refresh=60gpupdate /target:computer /force❯ View Expected Console Output
Computer Policy update has completed successfully.Step 4: Confirm Client and Collector Status
Verify the Source Connected and Events Arrived
VerificationAllow time for the configured refresh interval. On a pilot client, inspect the Eventlog-ForwardingPlugin Operational log for a successful subscription connection. On the collector, check the subscription runtime status and query ForwardedEvents for the pilot host.

Figure 3: Event Viewer ForwardedEvents log populated with incoming events showing client computer hostnames and details.
wecutil gr WEF-Pilot-System-EventsGet-WinEvent -LogName ForwardedEvents -MaxEvents 20 | Select-Object TimeCreated, MachineName, Id, LevelDisplayName❯ View Expected Console Output
Runtime status reports the pilot source as active; forwarded records show the source machine name.See Microsoft’s source-initiated subscription guide and wecutil reference for configuration and runtime status details.