Members of this built-in Windows group are allowed to read event logs. Windows Event Forwarding can only forward the Security log when Network Service has been added to it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Event Log Readers in context, with comparison tables and the common traps.
Terms in this definition
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Event subscription
Defines which events a Windows Event Collector gathers and from which source machines; they land in Forwarded Events on the collector.
- NETWORK SERVICE
Built in to Windows with limited rights; when it connects to other machines it uses the computer account's identity.