This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.
This service also exists in Windows 10, 11, 7 and Vista.
| Windows 8 edition | Windows 8 | Windows 8.1 | Windows 8.1 Update 1 |
|---|---|---|---|
| Core | Manual | Manual | Manual |
| Pro | Manual | Manual | Manual |
| Enterprise | Manual | Manual | Manual |
| Display name: | Windows Event Collector |
| Service name: | Wecsvc |
| Type: | share |
| Path: | %WinDir%\system32\svchost.exe -k NetworkService |
| File: | %WinDir%\system32\wecsvc.dll |
| Error control: | normal |
| Object: | NT AUTHORITY\NetworkService |
| Privileges: |
|
The Windows Event Collector service runs as NT AUTHORITY\NetworkService in a shared process of svchost.exe. Other services might run in the same process. If Windows Event Collector fails to start, the error is logged. Windows 8 startup proceeds, but a message box is displayed informing you that the Wecsvc service has failed to start.
Windows Event Collector won't start, if the following services are stopped or disabled:
1. Select your Windows 8 release and edition, and then click on the Download button below.
2. Save the RestoreWindowsEventCollectorWindows8.bat file to any folder on your hard drive.
3. Right-click the downloaded batch file and select Run as administrator.
4. Restart the computer.
Note. Make sure that the wecsvc.dll file exists in the %WinDir%\system32 folder. If this file is missing you can try to restore it from your Windows 8 installation media.