5.34 (L2) Ensure 'Windows Event Collector (Wecsvc)' is set to 'Disabled'

Information

This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log.
The recommended state for this setting is: Disabled.
Rationale:
In a high security environment, remote connections to secure workstations should be minimized, and management functions should be done locally.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled.
Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Windows Event Collector
Impact:
If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
Note: Many remote management tools and third-party security audit tools depend on this service.
Default Value:
Manual
CIS Controls:
Version 6
9.1 Limit Open Ports, Protocols, and Services
Ensure that only ports, protocols, and services with validated business needs are running on each system.
Version 7
9.2 Ensure Only Approved Ports, Protocols and Services Are Running
Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.

See Also

https://workbench.cisecurity.org/files/2288