mike86 Posted October 14, 2015 Posted October 14, 2015 Wondering if anyone has any advice on the best way to pull all the event log file information from multiple servers into one place and set up alerts. Any software recommendations etc? Thanks
Firefox Posted October 14, 2015 Posted October 14, 2015 Operations Manager with Audit Collection Services. Could be an expensive setup, depending on what MS products you are already licensed to use. OpsMgr comes under the System Center stack. 1
pete Posted October 14, 2015 Posted October 14, 2015 It depends if you know what you want to alert on or if this is just your spidey sense tingling/the feeling that you should have this information readily available. Windows natively supports log shopping (event log forwarding) to another server and alerting based on specifics you set (send me an email when X happens). Otherwise there's Splunk (the free version), Graylog, ELK (Elasticsearch, Logstash & Kibana), OSSEC*...etc and that's off the top of my head. It depends how much time/money you can allocate to the project. * Contains host-based IDS too, can involve faff but it's very** thorough. ** You'll need to tune it. 1
DarrenShan Posted October 14, 2015 Posted October 14, 2015 Have a look at Event Log Explorer (Windows event log management software, monitor system, application and security event logs — FSPro Labs) 1
DavR Posted October 15, 2015 Posted October 15, 2015 In a previous job I had CentraStage to play with, that did some quite good stuff around Event Monitoring, you know "if Event ID 123 occurs, do the following Email | Run Task | Etc". In that way I put Event Monitors on all our servers for particular events, notably disk failures etc. Probably wouldn't buy the whole product just for that though. 1
CyberNerd Posted October 15, 2015 Posted October 15, 2015 I've had good success with splunk in a previous life. 1
mike86 Posted October 15, 2015 Author Posted October 15, 2015 Cheers for your advice guys, lots to look into, going to start with Splunk, if only for the name...
DavR Posted October 15, 2015 Posted October 15, 2015 Cheers for your advice guys, lots to look into, going to start with Splunk, if only for the name... Be VERY careful how you type that one into Google.... one typo could send you down the wrong path! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now