Hi,
I have 12+ Domain Controller in my prod environment and I need to enable Event log subscription on all my DC's to forward security event log to central location. The purpose of this is, I need to capture all security log, so that it will be easy for me to check if anyone performing unwanted activities in DC's like addition, deletion etc.
OS : Windows server 2008 R2 SP1
Can anyone suggest is this the right way ?
Also Please let me know what all the prerequisites required to configure this ?