Applies to: Windows Clients only. macOS and Linux Clients log to their native OS log facilities (Apple System Log, syslog, journald) but don’t have an explicit integration parameter - those facilities are read directly by appropriate log collectors.
Where to find it
The Send log messages to Windows Event log checkbox lives on the Editing Client / Editing Client Group page, on the Properties tab, in the Windows Event log integration section.Configuring the log level
When enabled, the Log Level drop-down list selects the severity level cutoff - only messages at or above this level are written to the Windows Event Log.
The default Error level is the conservative choice - only significant operational problems get forwarded, minimizing noise in your central log collection.
What forwarded messages look like
Forwarded entries appear in the Windows Event Log with the EkranSystem source (or equivalent - the legacyEkranSystem source name is preserved in current Syteca versions for backward compatibility with existing log filters).
Common SIEM tools (Splunk Universal Forwarder, Microsoft Sentinel agent, IBM QRadar WinCollect, Elastic Beats) pick up the events alongside other Windows Event Log entries without additional configuration once the Client integration is enabled.
Related
SIEM integration
Direct Syteca-to-SIEM integration that bypasses the Event Log entirely.
Audit log
The Syteca administrative audit log (separate from operational Client events).
Windows Clients
Full Windows Client documentation.
Disconnected Client detection
Email-based notifications for Client-health issues - complementary to log-based monitoring.