The Windows Event Collector (WEC) for syslog-ng Premium Edition (syslog-ng PE) currently has the following limitations:
-
Only source-initiated push subscriptions are supported (Windows hosts connect to the WEC server).
An advantage of this, however, is that this requires less firewall rules.
-
The compression of events is not supported.
-
The batchsizelimit and batchtimeoutlimit options are not enforced on the Windows host side: Windows is handling these values only as a recommendation.
For more information, see batchsizelimit and batchtimeoutlimit in the subscriptions option in Configuring Windows Event Collector.
-
WEC cannot work in different authentication modes at once: either Kerberos authentication, or the certificate-based authentication is configured.
-
Kerberos authentication does not work in a WEC cluster deployment.
-
There is a known issue. After several reconnects (if WEC is restarted quickly), the remote sender can stop forwarding the logs for a certain period of time. In this case, restarting the Windows RM service can help.
This issue can also occur between two Windows machines. It has been reported to Microsoft and is awaiting resolution.