Submit a ticketCall us

AnnouncementsAre You “Flying Blind?”

When it comes to your complex IT infrastructure, you want to ensure you have a good grasp of what’s going on to avoid any fire drills that result from guesswork. Read our white paper to learn how proactively monitoring your IT environment can help your organization while giving you peace of mind.

Get your free white paper.

Home > Success Center > Kiwi Syslog Server > Kiwi Sys - Knowledgebase Articles > Log Forwarder for Windows

Log Forwarder for Windows

Table of contents

Updated: August 17, 2018


Event Log Forwarder for Windows is a tool that runs on a Windows system, forwarding event log records to a Syslog Server via UDP (User Datagram Protocol) or TCP (Transmission Control Protocol). 


It can be used to send syslog messages to NPM Server or Kiwi Syslog Server.


Event Log Forwarder for Windows can run on the following Windows operating system versions (both x86 and x64 editions are supported):

  • Windows 10
  • Windows 8 | Windows 8.1
  • Windows 7 | Windows 7 SP1
  • Windows Server 2016
  • Windows Server 2012 | 2012 R2
  • Windows Server 2008 | 2008 SP2 | 2008 R2 | 2008 R2 SP1 *
  • Windows Server 2003 R2 SP2 *

For more information on supported software, see Windows Server Support.



Event Log Forwarder for Windows is a tool that runs on a Windows system, forwarding event log records to a Syslog Server via User Datagram Protocol (UDP) or Transmission Control Protocol (TCP).


Event Log Forwarder for Windows comprises of two standard application executables (.exe):

  • The Service (LogForwarder.exe)
  • The User Interface (LogForwarderClient.exe)


Event Log Forwarder for Windows Service is named "SolarWinds Event Log Forwarder for Windows" and is installed and started during the installation process. To check or to manage Event Log Forwarder for Windows Service (start, stop, restart etc.) is via Windows Services manager or Windows command prompt: Net Start "ServiceName".


The Event Log Forwarder for Windows User Interface (UI) allows you to configure the Service, can (depending on which options were selected during installation) be opened using the SolarWinds Event Log Forwarder for Windows desktop shortcut item, the Quicklaunch item, or from the SolarWinds Event Log Forwarder for Windows Program group accessible from the Windows Start button.


Event Log Forwarder for Windows supports forwarding of both Windows Eventing 5 and 6 event records.

  • Windows eventing 5 Event Log records - > Windows O/S versions prior to Windows Vista and Windows Server 2008
  • Windows eventing 6 ("Crimson") Windows Event Log records - > versions of Windows based on the Windows NT 6.0 kernel (Windows Vista and Windows Server 2008, 2012)




Last modified