Windows event source configured as per WinRM configuration guide and Test connection success. However, logs are not coming to NetWitness due to below errors in Collector.
Sep 16 09:32:58 VLC NwLogCollector: [WindowsCollection] [failure] [windowshost] Bookmarks received: Application=204,Security=1,System=108
Sep 16 09:32:58 VLC NwLogCollector: [WindowsCollection] [failure] [windowshost] [processing] [WorkUnit] [processing] Remote event source [windowshost] has returned bookmark as '1' for one or more channels which maye be an error.Discarding pulled events and reverting bookmarks for all channels to previous known bookmarks.
This issue is due to read events access was not granted for security channel logs for Event Log Readers group and Network Service account.
Please follow the below steps to grant read events access to the security channel.
Login to the Windows server. Run the below commands as Administrator from the command prompt.