Jump to content

Recommended Posts

Posted

Hi Guys,

 

I've been looking round trying to find a few guides to Best Practice in capturing event logs in Windows (Servers and Clients) I've found a little but I was hoping one of you could point me in the right direction.

 

I'm looking for info on what I should be logging in general and specifically security wise. How big the log files generally need to be (I know, I know how long is a piece of string etc...;) )

 

I would need to log events from Windows 7 and 8.

 

Windows Servers DC, DNS, DHCP, Active Directory, MS SQL, Oracle SQL, MySQL, SharePoint, Exchange, Print Servers, File Replication Services, File Servers in general, Application servers, IIS and Citrix XenMobile and Xen App?

 

Thoughts ideas and reference points greatly appreciated.

 

 

Wes

Posted

All depends on what you're trying to log. You need to be specific about the sort of activity you're trying to capture.

 

You mention security-wise - but are you looking for malicious network traffic, attempted logons, auditing logons to machines, all of the above?

 

To be honest it sounds to me that you might be looking for a monitoring solution like Nagios, although that doesn't help to specify what you'll actually be logging.

Posted

All of the above if windows event logs can do it, also service restarts when failing etc.. Full Auditing really and all of this via GPO settings if possible. We use AD Audit Plus for reporting on the Events, however, WMI settings on the servers need to be changed to really get the best out of the system. We are also looking into a SIEM as well to allow us a central logging system for all devices windows/unix/switches/routers. However to give the best information I need to know how to configure the windows servers and clients to capture all of the events that may be needed. In the end I suppose it's trying to separate what's important on/to every individual server for us to report on.

 

So to cut a long story short I suppose I'd like to know what would be considered extremely important to monitor on:

 

DCs,

SQL Servers

Exchange Servers

Windows 7 & 8 clients

 

Then work out the log file storage requirements of each event log on each server?

 

After that I would also look to get a system to archive these off after a set amount of time.

 

 

Wes

Posted

Having re-read my original thread I'm really looking for what would be the more sensible approach to logging security events in regards to intrusion detection on clients, member servers and domain controllers. What is the best level of granularity to audit so that a lot of useful information is stored but we cut down to the minimum of erroneous logs? What would be a sensible starting size for these security logs?

 

Wes

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...