Windows Event Collector : Subscribed to only one out of 2 subscriptions

K. SA 1 Reputation point
2022-07-29T09:20:44.553+00:00

Hello everyone,

I have an issue with Windows Event Collector.

Context :

There are around 500 source servers (push mode), configuration is good, with 2 subscription (call A and B in this post) from the same collector (there is only 1 collector).

So the problem is :

Some servers (about 100) are subscribed to only one subscription (A). The other subscription (B) is not applied on these servers. It is applied only to others (about 400).
There is no significant difference between these 100 servers and the others.

In the "Eventlog-ForwardingPlugin" event log, we can see that the 100 source servers do receive the request for subscription A. But there is no interaction with subscription B. No error, no attempt to subscribe etc... It does not appear on any log. Even after some gpupdate
After days of investigation, there is no element of WEC configuration error.

So my question are :

  1. Is it possible to know where the XML queries received from a collector subscription are stored? In this way, it might be possible to force the registration of the query in the defective sources.
  2. Do you know a way to decrypt the HTTP traffic used by WinRM? (Encrypted thanks to Kerberos and wrapped in HTTP)
  3. Do you have any idea how i can solve this problem?

Thanks for reading

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,709 questions
Windows for IoT
Windows for IoT
A family of Microsoft operating systems designed for use in Internet of Things (IoT) devices.
381 questions
{count} votes