The log entries are also sent to the Windows application event log. Step 1: Add the network service account to the domain Event Log Readers Group. Event Log Forwarder for Windows comprises of two standard application executables (.exe): The Service (LogForwarder.exe) It runs as a Service monitoring the Windows Event Log and forwarding the messages to a syslog server. This delay may be caused by the subscription configuration, such as the DeliveryMaxLatency parameter, the performance of the collector, the forwarder, or the network. You can use event log forwarding feature which was introduced in Windows Server 2008. It sends events - based on the event source, event ID, users, computers, and keywords in the event - to your syslog server and allows you to take … The biggest advantage of EventLog Analyzer is that it can function as both a syslog server and a forwarder. Open Active Directory Users and Computers, navigate to the BuiltIn folder and double-click Event Log Readers. – Before clicking the Start button you can select which type of event logs you want to be forwarded to your your Syslog Server; it could be System logs, Security Logs, Application Logs … – open Windows services to check that the SyslogAgent is added and running. The policy for Windows Application Event logs is currently under development, so we will use a Log Source Type of "Syslog – Other" to process the logs. 