Configure WinRM polling
Windows Remote Management (WinRM) is a protocol and set of services that enable remote management of Windows systems.
Compared to WMI, WinRM:
- Works over HTTPS, so that you can validate the connection with an SSL certificate.
- Lets you apply different rules to different target machines, and restrict authentication type and port access.
- Polls faster for a single request.
- Supports multiple authentication mechanisms.
To configure WinRM, complete the following tasks:
Enable the WinRM service on servers
The WinRM service is not enabled by default on all Windows Server versions. Enable it on every device you want to monitor via WinRM, so the collector can establish a WinRM connection to poll data from it.
For instructions, see Enable-PSRemoting in Microsoft's PowerShell documentation.
Configure WinRM listeners on servers
WinRM uses listeners to accept incoming requests. By default, only an HTTP listener is created. Configure an HTTPS listener instead if you want to encrypt WinRM traffic. This requires installing an SSL certificate on the device first.
Complete this configuration on every device you want to monitor via WinRM.
For instructions, see Installation and configuration for Windows Remote Management in Microsoft's documentation.
Configure firewall exceptions
By default, WinRM traffic uses TCP port 5985 (HTTP) or 5986 (HTTPS). You can configure custom ports in host settings.
Make sure the firewall on each monitored device allows traffic on the configured port. If your Network Collector server is under a strict outbound policy, also allow outbound connections on these ports from the Network Collector server.
For instructions, see New-NetFirewallRule in Microsoft's PowerShell documentation.
Set trusted hosts
If a device isn't part of a domain, Kerberos mutual authentication isn't available, so WinRM can't automatically verify the identity of the remote computer. In that case, add each device to the trusted hosts list on both the monitored device and the Network Collector machine.
Setting all hosts as trusted (using a wildcard) is not recommended in production environments. Restrict the list to specific IP addresses or hostnames wherever possible.
For instructions, see Installation and configuration for Windows Remote Management in Microsoft's documentation.
Configure authentication
WinRM supports multiple authentication methods, such as:
-
Kerberos - recommended for domain environments.
-
NTLM - a fallback for non-domain environments.
-
Basic - requires HTTPS to secure credentials.
Enable the method or methods that match your environment on the devices you want to monitor.
For a list of supported options, see Authentication Mechanism, in the Polling Settings topic of the SolarWinds Platform documentation.
For instructions, see Authentication for Remote Connections in Microsoft's documentation.
Test WinRM configuration and connectivity
Before you rely on WinRM for polling, confirm that it's configured correctly and that the polling engine can reach the target device. Check the local WinRM configuration, then test connectivity both locally and to the remote target device.
For instructions, see Test-WSMan in Microsoft's PowerShell documentation.
Advanced configuration
Adjust WinRM timeout and connection limits
In environments with heavy polling loads, the default WinRM operation and idle-timeout limits may be too restrictive. Increase the maximum concurrent operations and the idle timeout to match your polling volume.
For instructions, see Installation and configuration for Windows Remote Management in Microsoft's documentation.
Enable CredSSP
If you're delegating credentials for remote commands (for example, a command that itself needs to reach another remote resource), enable CredSSP on both the polling engine and the target device.
For instructions, see Enable-WSManCredSSP in Microsoft's PowerShell documentation.