EventAdmin does not use any specific TCP/UDP ports. It only uses the standard Windows "copy" procedure. Below are the NetBios ports used by Windows for copying. These ports should be opened bi-directionally for Intrust to collect event logs:
netbios-ns 137/tcp nbname #NETBIOS Name Service
netbios-ns 137/udp nbname #NETBIOS Name Service
netbios-dgm 138/udp nbdatagram #NETBIOS Datagram Service
netbios-ssn 139/tcp nbsession #NETBIOS Session Service
You can verify that the correct ports are open by using Event Viewer on the Intrust machine to connect to the machine being collected against.