Jump to content

Recommended Posts

Posted

Wondering if anyone has any advice on the best way to pull all the event log file information from multiple servers into one place and set up alerts.

 

Any software recommendations etc?

 

Thanks

Posted
Operations Manager with Audit Collection Services. Could be an expensive setup, depending on what MS products you are already licensed to use. OpsMgr comes under the System Center stack.
  • Thanks 1
Posted

It depends if you know what you want to alert on or if this is just your spidey sense tingling/the feeling that you should have this information readily available.

 

Windows natively supports log shopping (event log forwarding) to another server and alerting based on specifics you set (send me an email when X happens).

 

Otherwise there's Splunk (the free version), Graylog, ELK (Elasticsearch, Logstash & Kibana), OSSEC*...etc and that's off the top of my head. It depends how much time/money you can allocate to the project.

 

* Contains host-based IDS too, can involve faff but it's very** thorough.

** You'll need to tune it.

  • Thanks 1
Posted

In a previous job I had CentraStage to play with, that did some quite good stuff around Event Monitoring, you know "if Event ID 123 occurs, do the following Email | Run Task | Etc". In that way I put Event Monitors on all our servers for particular events, notably disk failures etc.

 

Probably wouldn't buy the whole product just for that though.

  • Thanks 1
Posted
Cheers for your advice guys, lots to look into, going to start with Splunk, if only for the name...

 

Be VERY careful how you type that one into Google.... one typo could send you down the wrong path! ;)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...