Windows Event Forwarding - Are the local events kept on the local computer/server? RRS feed

  • Question

  • My organization is thinking about enabling event forwarding to a Windows Event Collector.  We also have deployed Arcsight in our environment that is agentless and pulls logs from our servers.  I cannot find an answer to the question of Do the local even logs stay on the local machine?  Does Windows Event Forwarding forward a copy of the event to the Collector and keep a copy locally in the event log?  Or if we enable Windows Event Forwarding on a server/PC, all the events specified will be forwarded to the Collector and the local event log will be empty?


    Thanks for the clarification!



    Wednesday, November 16, 2011 10:01 PM