Because each User-ID agent can monitor up to 100 servers,
the firewall needs multiple User-ID agents to monitor a network
with hundreds of AD domain controllers or Exchange servers. Creating and
managing numerous User-ID agents involves considerable administrative
overhead, especially in expanding networks where tracking new domain
controllers is difficult. Windows Log Forwarding enables you to
minimize the administrative overhead by reducing the number of servers
to monitor and thereby reducing the number of User-ID agents to
manage. When you configure Windows Log Forwarding, multiple domain
controllers export their login events to a single domain member
from which a User-ID agent collects the user mapping information.