Re: Managing Windows Event Logs

From: Pipes Cuchifrito (pipes_at_rapturesecurity.com)
Date: 06/24/03

  • Next message: Chris Carlson (OTG): "RE: Windows 2000 password policy"
    To: Chuck Meeusen <cmeeusen@optonline.net>
    Date: Mon, 23 Jun 2003 20:58:11 -0700
    
    

    Check out,

    http://ntsyslog.sourceforge.net

    For gathering the logs.

    I havent used this past testing, but seems to be stable enough.

    As for archiving, I don't think you could go past
    http://msyslog.sourceforge.net. I know this isn't an ideal solution for
    windows centric networks, but if the shoe fits....

    p

    Chuck Meeusen writes:

    > This discussion on event logs hits home for me. I'm attempting to
    > build a system of gathering and archiving the event logs from a
    > number (15 at present but must scale to 30-40) of NT and 2K
    > servers.
    > It's not pretty.
    >
    > My main source of information has been a document prepared for a
    > SANS course called "Centralizing Event Logs on Windows 2000" by
    > Greg Lalla. He scripts dumpevt.exe which I've found to be very
    > effective and then bcp's the csv's into a SQL dbase.
    >
    > So I'm wondering what anyone else is doing to gather logs and
    > archive?
    >
    > C.
    >
    >
    > -----------------------------------------------------------------------------
    > ------------------------------------------------------------------------------
    >
     

    Pipes
    Rapturesecurity.com

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Chris Carlson (OTG): "RE: Windows 2000 password policy"

    Relevant Pages

    • Re: Problem with alarmprogram.bat on Windows
      ... and the Alarmprogram.bat for logical log backups. ... of logs are needed to be backed up. ... up until the entire process of archiving data is over. ...
      (comp.databases.informix)
    • Re: Discussion on Mod 27 usage
      ... DB2 was logging faster than archiving could empty the logs ... justification in their storage management demands. ...
      (bit.listserv.ibm-main)
    • Re: Limiting the the size of log files
      ... multiple backups of those already archived. ... Archiving is done at best once a month. ... Archiving non-current logs is very ... but you said you'd trim to 10K. ...
      (comp.sys.acorn.programmer)
    • Re: Cleaning out the Clutter, Bad Mail and UCEArchive (IMF), Message tracking log folders...
      ... Gives you the option of deleting or archiving. ... Pre SP1 the behaviour was different and badmail was archived. ... >> folder so don't code anything yourself. ... >> Tracking Logs. ...
      (microsoft.public.exchange2000.admin)
    • Re: ESS and DB2 Log offload
      ... > On top of that, the read and write rate of your logs was limited to ESCON, ... However, going to and coming from the same cache, I expected the reads to be served at the same higher Ficon rate. ... > With the change to 3390-27 I hazard a guess that you are archiving and ... This is less likely a problem than sibling pend. ...
      (bit.listserv.ibm-main)