Re: Windows event auditing and reporting



For a good general starter, check out the "Library" section of
www.loganalysis.org. In particular, take a look at the various Event
Log to Syslog translators and subsequent Syslog reporting tools.

The reason I recommend conversions to Syslog are that it's a
well-known and well-supported format for open-source and commercial
tools of the type you're looking for. Additionally, it's the de-facto
logging standard for just about everything outside of the MS world -
e.g. Routers, Switches, most IDS, Unix, etc.

Once you get your logs into a generally vendor-agnostic format such as
Syslog, you open up numerous options that won't be otherwise
available, all the while keeping in tact those options that exist on
your platform of choice, such as LogParser, WMIC, EventcombMT, DUMPEL,
ELOGDUMP, etc. which can still be used in conjunction with your
overall log centralization, corrolation, and reporting facilities.

My two cents.

RE

On 4/3/06, rs <rsmade@xxxxxxxxx> wrote:
Can anyone recommend a good tool that will alert and report on Windows
Event logs, especially DC logs for events such as New user accounts,
changed user accounts, deleted user accounts, locked user accounts,
failed login attempts, expired passwords, dormant accounts, etc. We have
looked at both S.E.L.M from GFI (Reporting wasn't great) and Active
Administrator from ScriptLogic (Reporting was great but event criteria
was not customizable and it offers a ton of nice features that we don't
necessarily need but would be paying for.) . Just wanted to see if there
was anything else out there that someone could recommend?

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Windows event auditing and reporting
    ... Microsoft Windows NT based products all can use System Monitor, it's built in and provides a facility to set up trace logs ... Windows Event logs, especially DC logs for events such as New user accounts, changed user accounts, deleted user accounts, locked user accounts, failed login attempts, expired passwords, dormant accounts, etc. ... The Norwich University program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. ...
    (Security-Basics)
  • RE: audit trails for file access
    ... I actually use NTSyslog to send my logs off to a syslog server, ... On the syslog server side, I use syslog-ng to log to a MySQL database. ... In regards to logging to another machine, use the Eventlog to Syslog ...
    (Focus-Microsoft)
  • Re: Program to monitor employee internet usage
    ... And there are many programs doing analysis of it's logs for the reports. ... education and the case study affords you unmatched consulting experience. ... The Norwich University program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. ... Tailor your education to your own professional goals with degree customizations including Emergency Management, Business Continuity Planning, Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: Users missing Exchange mailbox still there
    ... and with no outside assistance deletes user accounts. ... Strange that the audit logs didn't capture anything. ... >>> through the event logs, syslogs, firewall syslogs, as well as our ... and recreated profiles on the PC's. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cisco ASA Syslog Messages
    ... syslog log files and alert us based on specific queries. ... look for in the logs. ... take a look at some of the PIX syslog tools at ...
    (comp.dcom.sys.cisco)