Managing Windows Event Logs

From: Chuck Meeusen (cmeeusen_at_optonline.net)
Date: 06/20/03

  • Next message: Laura A. Robinson: "RE: Filtering DHCP Assignments by MAC Address"
    Date: Fri, 20 Jun 2003 16:28:03 -0400
    To: "focus-ms@securityfocus.com" <focus-ms@securityfocus.com>
    
    

    This discussion on event logs hits home for me. I'm attempting to
    build a system of gathering and archiving the event logs from a
    number (15 at present but must scale to 30-40) of NT and 2K
    servers.
    It's not pretty.

    My main source of information has been a document prepared for a
    SANS course called "Centralizing Event Logs on Windows 2000" by
    Greg Lalla. He scripts dumpevt.exe which I've found to be very
    effective and then bcp's the csv's into a SQL dbase.

    So I'm wondering what anyone else is doing to gather logs and
    archive?

    C.

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Laura A. Robinson: "RE: Filtering DHCP Assignments by MAC Address"

    Relevant Pages

    • Re: Managing Windows Event Logs
      ... I decided to stay with the process I cited from SANS because 1). ... tools (except for SQLServer of course, but we already own that) 2.) it keeps ... > build a system of gathering and archiving the event logs from a ...
      (Focus-Microsoft)
    • RE: Managing Windows Event Logs
      ... We've just implemented MOM. ... Subject: Managing Windows Event Logs ... a system of gathering and archiving the event logs from a number (15 at ...
      (Focus-Microsoft)