{"id":506,"date":"2021-11-03T18:04:39","date_gmt":"2021-11-03T18:04:39","guid":{"rendered":"https:\/\/eventlogxp.com\/blog\/?p=506"},"modified":"2021-11-04T15:36:30","modified_gmt":"2021-11-04T15:36:30","slug":"setting-up-windows-to-read-events-from-remote-computers-over-a-local-network","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/setting-up-windows-to-read-events-from-remote-computers-over-a-local-network\/","title":{"rendered":"Setting up Windows to read events from remote computers over a local network."},"content":{"rendered":"\r\n<p>Reading event logs from remote computers is crucial for network audit. Both Event Log Explorer and Windows Event Viewer applications allow the system administrators to read event logs remotely. However sometimes (mainly in no Active Directory environment) sysadmins have problems with accessing remote event logs. In this article, I\u2019ll explain how to setup Windows to make event logs accessible over a network.<\/p>\r\n\r\n\r\n\r\n<p>As a rule, you don\u2019t need to change anything on your client computer (the computer on which you run Event Log Explorer or Windows Event Viewer). All the changes should be done on the audited computer.<\/p>\r\n\r\n\r\n\r\n<p>First, you need to set up the firewall.<\/p>\r\n\r\n\r\n\r\n<p>Run Windows application: Windows Defender Firewall with Advanced Security.<\/p>\r\n\r\n\r\n\r\n<p>Select Inbound rules for your profile<\/p>\r\n\r\n\r\n\r\n<p>Enable the following inbound rules:<\/p>\r\n\r\n\r\n\r\n<ul>\r\n<li>Remote Event Log Management (RPC)<\/li>\r\n<li>Remote Event Log Management (RPC-EPMAP)<\/li>\r\n<li>Remove Event Monitor (RPC)<\/li>\r\n<li>Remote Event Monitor (RPC-EPMAP)<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings.png\" data-rel=\"lightbox-gallery-DjDbq8Oa\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"wp-image-507\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings.png\" alt=\"\" width=\"813\" height=\"225\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings.png 813w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings-300x83.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings-768x213.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/firewall_settings-660x183.png 660w\" sizes=\"(max-width: 813px) 100vw, 813px\" \/><\/a><\/figure>\r\n\r\n\r\n\r\n<p>Note that these settings are applied locally. If you run Active Directory and want to change these settings globally, you can do it in a similar way using Group Policy Management Editor.<\/p>\r\n\r\n\r\n\r\n<p>Next, if you have a serverless network, you should check sharing and security model for local accounts. \u00a0Open Local Security Policy, select Local Policies-&gt;Security Options in the left pane and make sure that the policy \u201cNetwork access: Sharing and security model for local accounts\u201d is set to Classic \u2013 local users authenticate as themselves.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic.png\" data-rel=\"lightbox-gallery-DjDbq8Oa\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"wp-image-508\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic.png\" alt=\"\" width=\"854\" height=\"674\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic.png 854w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic-300x237.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic-768x606.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/sharing_and_security_classic-660x521.png 660w\" sizes=\"(max-width: 854px) 100vw, 854px\" \/><\/a><\/figure>\r\n\r\n\r\n\r\n<p>Finally, you should grant permission to read event logs to your users. In no Active Directory environment, you can use Computer Management. In AD use Active Directory Users and Computers console.<\/p>\r\n\r\n\r\n\r\n<p>Select the user under Local Users and Groups (or under your domain users). Double click on it to display Properties and select Member Of. Click Add and type Event Log Readers.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/EventLogReaders.png\" data-rel=\"lightbox-gallery-DjDbq8Oa\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"wp-image-509\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/EventLogReaders.png\" alt=\"\" width=\"485\" height=\"458\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/EventLogReaders.png 485w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2021\/11\/EventLogReaders-300x283.png 300w\" sizes=\"(max-width: 485px) 100vw, 485px\" \/><\/a><\/figure>\r\n\r\n\r\n\r\n<p>That\u2019s all. If you modified Group Policy settings, you should apply your changes (e.g. by using gpupdate command).<\/p>\r\n\r\n\r\n\r\n<p>Now you can start Event Log Explorer or Windows Event Viewer and open remote event logs.<\/p>\r\n\r\n\r\n\r\n<p><a href=\"https:\/\/eventlogxp.com\/download.php\" target=\"_blank\" rel=\"noreferrer noopener\">Download Event Log Explorer<\/a> right now and check the benefits it brings compared to Windows Event Viewer.<\/p>\r\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;t=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2021%2F11%2Fnetwork-firewall.jpg&#038;p&#091;title&#093;=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;title=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2021%2F11%2Fnetwork-firewall.jpg&#038;description=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506&#038;title=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Setting%20up%20Windows%20to%20read%20events%20from%20remote%20computers%20over%20a%20local%20network.&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F506\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Reading event logs from remote computers is crucial for network audit. Both Event Log Explorer and Windows Event Viewer applications allow the system administrators to read event logs remotely. However sometimes (mainly in no Active Directory environment) sysadmins have problems with accessing remote event logs. In this article, I\u2019ll explain how to setup Windows to make event logs accessible over a network. As a rule,\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/setting-up-windows-to-read-events-from-remote-computers-over-a-local-network\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":512,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[76,77,78],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/506"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=506"}],"version-history":[{"count":3,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/506\/revisions"}],"predecessor-version":[{"id":514,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/506\/revisions\/514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/512"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}