Re: Win2k log management

From: Steve (securityfocus@delahunty.com)
Date: 01/28/03

  • Next message: Porter, Thomas L: "RE: Win2k log management"
    From: "Steve" <securityfocus@delahunty.com>
    To: "Hayes, Bill" <Bill.Hayes@owh.com>, <focus-ms@securityfocus.com>, <defaillance@hushmail.com>
    Date: Tue, 28 Jan 2003 13:02:42 -0500
    
    

    We run IPSentry http://www.ipsentry.com/ and like it. It sort-of meets your
    requirements but it also does network monitoring. You will want to look at
    the NT Event Log Monitor add-on
    http://www.ipsentry.com/scr/addins.asp?ID=ipsevmon. The configuration is
    very customizable. We use it to email us when anything is logged on any
    event log on any server that is warning level or above. This keeps us very
    proactive on server management. We have all the email delivered to several
    administrators.

    STEVE

    ----- Original Message -----
    From: "Hayes, Bill" <Bill.Hayes@owh.com>
    To: <focus-ms@securityfocus.com>
    Sent: Friday, January 24, 2003 5:09 PM
    Subject: RE: Win2k log management

    Perl offers the cheapest and most flexible solution. There are plenty of
    event log examples on the web that will help. It's also amazingly
    powerful and quick to learn. You can get Perl for Windows boxes from
    wwww.activeperl.com. The HTML-based help files contain coding examples.

    -----Original Message-----
    From: defaillance@hushmail.com [mailto:defaillance@hushmail.com]
    Sent: Friday, January 24, 2003 12:04 PM
    To: focus-ms@securityfocus.com
    Subject: Win2k log management

    -----BEGIN PGP SIGNED MESSAGE-----

    I am currently administering over 10 server(advanced) and 20 workstation
    (pro), The management of event/security/application log has become
    unbeareable,so im looking for a centralized management solution were the
    informatin would be gather from server/workstation to a specific server,
    so the question is: Anyone aware of such a software
    that could do the job ? commercial or freeware, I basically just want to
    avoid having to walk over to check them manually.

    also if anyone who has faced this situation is willing to share
    their knowledge on the subject...

    Thanks
    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.2 (Java)
    Note: This signature can be verified at https://www.hushtools.com/verify

    wl8EARECACAFAj4xf/sZHGRlZmFpbGxhbmNlQGh1c2htYWlsLmNvbQAKCRAAqpYJlh8f
    xQ7GAJ9+/LTX1k/uD/cY6mzx8iPKehJGhgCY8S0SZc03cmWwXsZwQBpQ8K7Rog==
    =4gCk
    -----END PGP SIGNATURE-----

    Concerned about your privacy? Follow this link to get
    FREE encrypted email: https://www.hushmail.com/?l=2

    Big $$$ to be made with the HushMail Affiliate Program:
    https://www.hushmail.com/about.php?subloc=affiliate&l=427



    Relevant Pages

    • Re: What are the best general things to do after a dirty shutdown (Server SBS)
      ... Microsoft Windows Small Business Server 2003 Best Practices Analyzer ... After that, please post any event log errors, just the EventID# and Source names, not the whole error message. ... error 15100 Win32 Error 15100. ... One is indicating it can't retrieve info about the System log. ...
      (microsoft.public.windows.server.sbs)
    • Re: What are the best general things to do after a dirty shutdown (Server SBS)
      ... test network connectivity to local domain controllers. ... Directory Server Diagnosis ... Verifying that the local machine ALPHA, ... The File Replication Service Event log test ...
      (microsoft.public.windows.server.sbs)
    • Re: What are the best general things to do after a dirty shutdown (Server SBS)
      ... Microsoft Windows Small Business Server 2003 Best Practices Analyzer ... After that, please post any event log errors, just the EventID# and Source names, not the whole error message. ... (Event String (event log = Directory Service) ...
      (microsoft.public.windows.server.sbs)
    • Re: Server2003 2008 error !!
      ... Remove the x.x.1.x form the NIC of the DCs and configure it as a FORWARDER or use directly the ISPs DNS server as Forwarders in the DNS server properties in the DNS management console. ... On the 2008 make sure the internal firewall is not blocking AD replication, by default the firewall is enabled ion 2008. ... The event log File Replication Service on server ... EventID: 0x000003EE ...
      (microsoft.public.windows.server.active_directory)
    • Re: What are the best general things to do after a dirty shutdown (Server SBS)
      ... Microsoft Windows Small Business Server 2003 Best Practices Analyzer ... After that, please post any event log errors, just the EventID# and Source names, not the whole error message. ... One is indicating it can't retrieve info about the System log. ...
      (microsoft.public.windows.server.sbs)