Windows Forwarding Event Requirements

GEORGE, Thomas 1 Reputation point
2021-04-26T08:22:51.787+00:00

Hello,

I am currently in an internship and I am studing CyberArk's PTA. For the lab I would use to illustrate the functionalities of the product, I need to use a Windows Forwarding Event Server.

But the problem is that I don't really know what are the requirements to be able to install WFE in a machine.

Can you please help me ?

Thank in advance !

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,726 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Carl Fan 6,836 Reputation points
    2021-04-28T09:42:43.907+00:00

    Hi,
    Some information provided on Microsoft Website:
    You deploy EventLog Forwarding in a large environment. For example, you deploy 40,000 to 100,000 source computers. In this situation, we recommend that you deploy more than one collector that has 2,000 to not more than 4,000 clients per collector.

    Additionally, we recommend that you install at least 16 GB of RAM and four (4) processors on the collector to support an average load of 2,000 to 4,000 clients that have one or two subscriptions configured.

    Fast disks are recommended, and the ForwardedEvents log can be put onto another disk for better performance.

    The memory usage of the Windows Event Collector service depends on the number of connections that are received by the client. The number of connections depends on the following factors:

    The frequency of the connections
    The number of subscriptions
    The number of clients
    The operating system of the clients
    For example, for the default values of 4,000 clients and five to seven subscriptions, the memory that is used by the Windows Event Collector service may quickly exceed 4 GB and continue to grow. This can make the computer unresponsive.
    Meanwhile, some information about setup WFE and Environment Requirements in the link below. Hope it could be helpful to you.
    https://adamtheautomator.com/windows-event-collector/
    Hope this helps and please help to accept as Answer if the response is useful.
    Best Regards,
    Carl

    0 comments No comments