+ Post New Thread
Results 1 to 3 of 3
Windows Thread, Manage Windows Security Event Logs in Technical; Currently we review event logs each day if we get time, this basically involves running a search for bad logon ...
  1. #1
    JamesMason's Avatar
    Join Date
    Nov 2009
    Posts
    18
    Thank Post
    9
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Manage Windows Security Event Logs

    Currently we review event logs each day if we get time, this basically involves running a search for bad logon attempts against the admin accounts and looking for repeated (hundreds) attempts against other accounts to look for virus like activity. We then archive the logs in case we need to return to them.

    How do you all manage your security event logs?
    Anyone using third party software to analise logs and flag certain conditions?

    Thanks.

  2. #2
    ArchersIT's Avatar
    Join Date
    Nov 2006
    Location
    Bedfordshire
    Posts
    114
    Thank Post
    14
    Thanked 24 Times in 20 Posts
    Rep Power
    21
    We dont do this, but we do something similar from time to time. For that we simply use Microsoft's Log Parser tool Download details: Log Parser 2.2. This allows you to run SQL like queries against the event logs which may speed up your processing.

    Hope that helps

    Jonathan

  3. #3
    gshaw's Avatar
    Join Date
    Sep 2007
    Location
    Essex
    Posts
    2,702
    Thank Post
    172
    Thanked 224 Times in 207 Posts
    Rep Power
    68
    I tried out Splunk for this... was pretty decent but new version is out now and should be a lot better

    Splunk | IT Search for Log Management, Operations, Security and Compliance

    Just don't typo on the name!!!

SHARE:
+ Post New Thread

Similar Threads

  1. Windows 2003 Event log error 680
    By tannajay in forum Windows Server 2000/2003
    Replies: 0
    Last Post: 3rd December 2009, 04:08 PM
  2. Essential tools to manage a Windows 2003/2008 domain?
    By reggiep in forum Windows Server 2000/2003
    Replies: 8
    Last Post: 6th May 2009, 09:47 AM
  3. Replies: 16
    Last Post: 27th March 2009, 12:35 PM
  4. Stopped security event log
    By Jobos in forum Windows
    Replies: 3
    Last Post: 10th September 2007, 12:48 PM
  5. Event Log Every 5 Mins in Windows 2k Server
    By mrtechsystems in forum Windows
    Replies: 11
    Last Post: 26th June 2005, 09:50 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •