Event forwarding failed

Spellbound vfx 6 Reputation points
2020-11-30T04:32:16.513+00:00

I have configured event forwarding in my server. All logs are forwarding except the security log. I have done all the troubleshooting procedures stated in forums like adding the user as a network log reader, registry settings, and permissions but end in vain. This is configured using the collector initiated method.I have also tried the source initiated method and received the following error in the event forwarding log.

The forwarder is having a problem communicating with subscription manager at address http://xxxxxx. Error code is 2150859195 and Error Message is <f:WSManFault xmlns:f="http://schemas.microsoft.com/wbem/wsman/1/wsmanfault" Code="2150859195" Machine="xxxxxxx"><f:Message>The WinRM client cannot process the request. Default authentication may be used with an IP address under the following conditions: the transport is HTTPS or the destination is in the TrustedHosts list, and explicit credentials are provided. Use winrm.cmd to configure TrustedHosts. Note that computers in the TrustedHosts list might not be authenticated. For more information on how to set TrustedHosts run the following command: winrm help config. </f:Message></f:WSManFault>.

can somebody explain what may be the error.Thanks in advance.

Windows Server Setup
Windows Server Setup
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
240 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2020-11-30T07:59:50.503+00:00

    Hi,

    If you tried source initiated, please follow below actions in this thread to see if it helps.

    1. use FQDN not the IP address of the collector.
    2. enable WinRM listeners policy, set both IPv4 and IPv6 value to *

    Do is there any error message when you configured using the collector initiated method?

    Thanks,

    Eleven

    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.

    0 comments No comments