localzuk Posted June 20, 2011 Posted June 20, 2011 I've got an issue here which I'm sure many of you also come across regularly - people get error messages on their screens and then simply report the computer as being 'broken'. When quizzed about what the message said, the response ranges from 'Computer something something' to 'I dunno, I didn't look'. So, in an effort to reduce this issue, I've been thinking about central event logging. Now I realise that this is going to be a lot of logging when you consider 250 computers all reporting back to one place, but at the same time, it will save a lot of time and effort, and I have the spare capacity to handle it. My question is this - do any of you do this already? If so, what do you use to do it?
chazzy2501 Posted June 20, 2011 Posted June 20, 2011 you can make a new MMC with event logs then link it to your remote PC. I create a new one if I need the remote error logs. of course thats only if the PC is still on line as the records will still be stored locally to that pc.
localzuk Posted June 20, 2011 Author Posted June 20, 2011 I don't really want to have to do this for all our PCs. I want a simple searchable log database with everything in.
chazzy2501 Posted June 20, 2011 Posted June 20, 2011 it takes about a full minute just to filter my local event log, I couldn't imagine how large the consolidated log would become and how slow it would be to use. it'd be cool though.
localzuk Posted June 20, 2011 Author Posted June 20, 2011 it takes about a full minute just to filter my local event log, I couldn't imagine how large the consolidated log would become and how slow it would be to use. it'd be cool though. My thought would be that the data would be imported into an SQL database, and then commands ran against that, so size wouldn't be a major issue.
Netman Posted June 20, 2011 Posted June 20, 2011 Lansweeper can do this IIRC, you might have to buy the premium version, rather than the free version to get it though. Although it is cheap and very good indeed... Free hardware inventory and software inventory for windows networks
FN-GM Posted June 20, 2011 Posted June 20, 2011 it takes about a full minute just to filter my local event log, I couldn't imagine how large the consolidated log would become and how slow it would be to use. it'd be cool though. The problem would be if the machine is off you cant get it. I used to work in a split site school and that was annoying. Also the machine dies and you want to get logs it is a hard task to do.
plexer Posted June 20, 2011 Posted June 20, 2011 What about something like this: winlogd - Windows EventLog to Syslog Service - Edoceo, Inc. Then you could use a syslog server to receive it. Ben
Arthur Posted June 20, 2011 Posted June 20, 2011 A few more... Windows Event Forwarding (included with Windows) EventSentry Splunk There's also PowerShell (Get-Eventlog etc.) and WEvtUtil, but these will only work if the PC in on.
RobBaxter Posted June 20, 2011 Posted June 20, 2011 hums .... No I just KNOW there was a huge bug of my MCITP on logging. You can set it up with log subscriptions directly to your DC.... this is something that i want to look at doing. So i will get on it asap and let you know how it goes!
BHMS Posted June 20, 2011 Posted June 20, 2011 I think Spiceworks can do this for you as it scans. At least there is a "number of events by day" widget so it's actually reading them as it scans your network.
SYNACK Posted June 20, 2011 Posted June 20, 2011 This is also avalible as part of the MDOP under MVLS SA Microsoft Windows Enterprise: System Center Desktop Error Monitoring costs a little extra though.
john Posted June 20, 2011 Posted June 20, 2011 I think Spiceworks can do this for you as it scans. At least there is a "number of events by day" widget so it's actually reading them as it scans your network.Indeed Spiceworks does collect them as part of its daily scans as you get some very colourful bar charts each day showing the types of log and machine groups etc and all for free
sven Posted June 21, 2011 Posted June 21, 2011 Indeed Spiceworks does collect them as part of its daily scans as you get some very colourful bar charts each day showing the types of log and machine groups etc and all for free Another vote for Spiceworks here. Best solution we have running on the network, and what's best is that it didn't cost us a penny. Love it.
chazzy2501 Posted June 29, 2011 Posted June 29, 2011 OK, I've installed spiceworks and have been using it for a week now. It's got great potential although I've yet to get it to see 2/3rds of my network (WMI Issues I think) But the asset managment, config tools...I'm loving it just for managing my printers! I've just intergrated active directory and got the ticket system running. And of course it's showing me events for my PCs. I'm using it as an excuse to tidy up my system Thumbs up!
cpjitservices Posted June 29, 2011 Posted June 29, 2011 The ticket system is brilliant I'm thinking of implementing it here and lifting it off my test server, had it up & running within 2 minutes and has the control we need. Spot on program - think I'm going to put it on a dedicated server though!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now