Windows Event Logs

From: Floyd Russell (floyd_at_neospire.net)
Date: 06/19/03

  • Next message: Jimmy Sansi: "RE: Filtering DHCP Assignments by MAC Address"
    To: <focus-ms@securityfocus.com>
    Date: Thu, 19 Jun 2003 13:27:59 -0500
    
    

    In my years of admining windows servers the event logs have always been
    frustratingly incomplete. This is especially true with the Security logs.
    For example if an attempted logon fails, it records the event, but seeminly
    nothing else of importance like an IP.
    Are there any tools out there that either allow admins a finer control over
    what activities happen on the host or any that can pull such information
    from the event logs?

    Thanks,
    Floyd R.

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Jimmy Sansi: "RE: Filtering DHCP Assignments by MAC Address"

    Relevant Pages

    • Re: Capturing interactive logons from Security Event Log
      ... reading the event logs in... ... Our security logs are large and processing that query is time consuming. ...
      (microsoft.public.scripting.vbscript)
    • Tracking the security logs for group attributes modifications
      ... I want to track the security logs for the modifications ... Hide/Unhide group memberships. ... changing the owner of the groups ... time with the event logs. ...
      (microsoft.public.win2000.active_directory)
    • Tracking the security logs
      ... I want to track the security logs for the modifications ... Hide/Unhide group memberships. ... changing the owner of the groups ... time with the event logs. ...
      (microsoft.public.win2000.active_directory)
    • Tracking the security logs
      ... I want to track the security logs for the modifications ... Hide/Unhide group memberships. ... changing the owner of the groups ... time with the event logs. ...
      (microsoft.public.exchange2000.win2000)