Re: Audit Logs Save Slowly and/or corrupt

From: Eric Fitzgerald [MSFT] (ericf@online.microsoft.com)
Date: 02/03/03


From: "Eric Fitzgerald [MSFT]" <ericf@online.microsoft.com>
Date: Mon, 3 Feb 2003 11:54:12 -0800


What version and service pack are you running? Any hotfixes installed?

If you're running Windows 2000, then use the Resource Kit utility DUMPEL.EXE
instead of saving to CSV. DUMPEL has a CSV output format option. If you're
using Windows XP, use the EventQuery.vbs utility that comes with Windows XP.

Can you be more clear on "corrupt"? Do you have a way to make the .evt file
and the .csv file available to us?

Thanks,

Eric

-- 
Eric Fitzgerald
Program Manager, Windows Auditing and Intrusion Detection
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"jt" <fury716@yahoo.com> wrote in message
news:03b601c2c6de$ac1e6e30$8ef82ecf@TK2MSFTNGXA04...
> Hi!
> For compliance purposes, I have to review then save the
> security audit logs for all systems which I administer.
>
> I review and save the files through the MMC.
>
> The audits logs are saved as CSV files. They are EXTREMELY
> slow to save (sometimes as long five minutes) and
> sometimes the saved file corrupts rather than saving
> properly.
>
> It's gotten to the point where most of my Monday mornings
> are spent waiting for the logs to save.
>
> I have no idea what's causing this. Any suggestions would
> be appreciated.
>
> Thanks!
>
> jt
>
>


Relevant Pages

  • Re: CSV Downloads
    ... Ramesh, Microsoft MVP ... Windows XP Shell/User ... Should you need to open a CSV file in Internet Explorer ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Contact list....lots of unknown contacts
    ... I have no idea, Jack...other than backing up your Contacts in a CSV file, editing the CSV file, deleting all existing Windows Contacts, importing the edited CSV file and then killing/uninstalling Plaxo so this doesn't happen again. ... Jack Reece wrote: ... machines Plaxo does the merging offsite on their ...
    (microsoft.public.windows.vista.mail)
  • Re: Parallels & Bootcamp; most efficient way to install Windows on new machine?
    ... scratch every time one moves from the OSX partition to the Windows ... different than saving the state of the entire OS so that a long restart ... Saving the state of a virtual machine is not "saving the ... What do you mean "a simulated restart"? ...
    (uk.comp.sys.mac)
  • Re: Start application & continue after app exits
    ... but I don't think all versions of Windows can handle opening ... doesn't make it secure because the file exists on disk and can be read. ... If you are worried about security, you would't be saving the file to the ...
    (comp.lang.python)
  • Re: WinXP desktop Security via policies
    ... file to their storage device, and create a shortcut to that file on the ... So..we are left with trying to stop them from saving to the ... how come you are using Zenworks? ... I work for a public/private highschool and we utilize the Windows ...
    (microsoft.public.windowsxp.security_admin)