Configuring Alert Forwarders

The Audit Collection Services does not start collecting security event data after installation of the audit collection server. The audit collection server install creates the following ACS components:

• Audit collection

• Audit collection database

It does not enable the third ACS component, which is the

• Audit forwarder

The audit forwarder is installed with each agent and the service is the System Center Audit Forwarding service, but is disabled by default, as shown in Figure 7.9. The service must be enabled through the console, which configures the audit forwarder to send security events to the correct audit collector and enables the service.

Figure 7.9 Disabled Audit Forwarding service.

The steps to enable the ...

Get Microsoft® System Center 2012 Unleashed now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.