JamesMason Posted December 9, 2009 Posted December 9, 2009 Currently we review event logs each day if we get time, this basically involves running a search for bad logon attempts against the admin accounts and looking for repeated (hundreds) attempts against other accounts to look for virus like activity. We then archive the logs in case we need to return to them. How do you all manage your security event logs? Anyone using third party software to analise logs and flag certain conditions? Thanks.
ArchersIT Posted December 10, 2009 Posted December 10, 2009 We dont do this, but we do something similar from time to time. For that we simply use Microsoft's Log Parser tool Download details: Log Parser 2.2. This allows you to run SQL like queries against the event logs which may speed up your processing. Hope that helps Jonathan
gshaw Posted December 10, 2009 Posted December 10, 2009 I tried out Splunk for this... was pretty decent but new version is out now and should be a lot better Splunk | IT Search for Log Management, Operations, Security and Compliance Just don't typo on the name!!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now