I'm setting up Windows Event Forwarding (WEF) utilizing a source initiated subscription type. In that source initiated subscription - select computer groups area I've successfully tested entering an individual PC. Additionally, if I enter Domain Computers in that filter it works as well. Based on several guides I've read it seems entirely possible to use an Active Directory security group that includes PCs. Added my test security group to that subscription - select groups area but it doesn't seem to work. The source computers counter never goes above 0 unless I go back to using the PC's name or Domain Computers in my selection.
"Why don't you just use domain computers?" Assumed that would hurt performance and/or clog the logs with PCs that I'm not deploying my WEF GPO (collector is at xyz address) to.
Any ideas?
https://support.logbinder.com/SuperchargerKB/50149/Controlling-Which-Computers-Subscribe-to-a-WEC-Subscription https://securityanalyststuff.wordpress.com/2019/03/31/windows-event-forwarding-notes/