How to configure Windows 2008 to control events

How to configure Windows 2008 to control events

If the program EventLog Analyzer is installed on a Windows 2008 server that does not belong to any Active Directory domain, in order to allow the program EventLog Analyzer to collect events generated from this server (localhost), you must disable the Windows 2008 Password Protected Sharing:

Password Protected Sharing

To do this you should:
  • connected to the server with administrative credentials on the server itself;
  • go to Control Panel and open the Network and Sharing Center;
  • expand the section Password Protected Sharing and select Turn off password protected sharing;
  • verify that Password Protected Sharing is disabled.
To collect events generated by a Windows 2008 server, you should activate the InBound Rule called Remote Event Log Management (RPC):

InBound EventLog Management (RPC) Rule

To enable the rule Remote Event Log Management (RPC) you should do the following:
  • connected to the server with administrative credentials on the server itself;
  • open Server Manager, expand the section Configuration, expand the section Windows Firewall with Advanced Security;
  • select the entry InBound Rules and enable the rule Remote Event Log Management (RPC).
Alessandro












                New to ADSelfService Plus?