Click here to get back home

Windows Server 2003 event logs

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Windows Server 2003 event logs Tom Penharston 05-02-2006
Posted by Tom Penharston on May 2, 2006, 3:29 pm
Please log in for more thread options
I'm running Windows Server 2003. I have some simple questions
regarding the log viewer snap-in.

Can I apply a negative filter? I've been working with the event viewer
for years, but I've never needed this feature as much as I do now, I
want to view all events, except a particular event ID (or set of
multiple event IDs).

Can I purge certain events from the logs? There are several random
events that I want to keep an eye on in case they occur again, but
there are several other, frequently occuring events that have been
resolved and can be purged permanently from the active log.

I know that I can save my logs. I also know that I can completely
clear my logs. However, these solutions don't offer the long-term
vision that I need.

How can I retain the less obvious errors for future reference, but
eliminate the mountains of obvious errors?

Are there third-party tools that help?


Posted by Steven L Umbach on May 2, 2006, 3:57 pm
Please log in for more thread options
You can use the free Event Comb from Microsoft to search for specific Event
IDs and you can use RK and third party tools to parse the security log for
events you are locking for such as PsLogList from SysInternals as shown in
first the link below that also shows syntax. --- Steve

http://www.sysinternals.com/Utilities/PsLogList.html
http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

--- Event Comb available here


> I'm running Windows Server 2003. I have some simple questions
> regarding the log viewer snap-in.
>
> Can I apply a negative filter? I've been working with the event viewer
> for years, but I've never needed this feature as much as I do now, I
> want to view all events, except a particular event ID (or set of
> multiple event IDs).
>
> Can I purge certain events from the logs? There are several random
> events that I want to keep an eye on in case they occur again, but
> there are several other, frequently occuring events that have been
> resolved and can be purged permanently from the active log.
>
> I know that I can save my logs. I also know that I can completely
> clear my logs. However, these solutions don't offer the long-term
> vision that I need.
>
> How can I retain the less obvious errors for future reference, but
> eliminate the mountains of obvious errors?
>
> Are there third-party tools that help?
>



Posted by Russ Grover - SBITS.Biz - \(MC on May 2, 2006, 4:02 pm
Please log in for more thread options
Cross posting doesn't usually get the best response,
But if you click on the TOP of the column it will sort them for you.

--
Russell Grover
SBITS.Biz
Enterprise Solutions for Small Business
Microsoft Certified Small Business Specialist.
MCP, MCPS MCNPS, (MCP-SBS)
Portland/Beaverton OR
MSN Messenger: Support at SBITS.Biz
Website: http://www.SBITS.Biz



> I'm running Windows Server 2003. I have some simple questions
> regarding the log viewer snap-in.
>
> Can I apply a negative filter? I've been working with the event viewer
> for years, but I've never needed this feature as much as I do now, I
> want to view all events, except a particular event ID (or set of
> multiple event IDs).
>
> Can I purge certain events from the logs? There are several random
> events that I want to keep an eye on in case they occur again, but
> there are several other, frequently occuring events that have been
> resolved and can be purged permanently from the active log.
>
> I know that I can save my logs. I also know that I can completely
> clear my logs. However, these solutions don't offer the long-term
> vision that I need.
>
> How can I retain the less obvious errors for future reference, but
> eliminate the mountains of obvious errors?
>
> Are there third-party tools that help?
>



Similar ThreadsPosted
Event ID 2003 Unable to open the performance logs and alerts confi May 30, 2006, 6:28 am
Security Event Logs June 10, 2005, 8:36 am
Rights to event logs June 15, 2005, 2:03 pm
security event logs in DC as well ? SOS May 3, 2006, 6:06 pm
Re: Access Deined event logs October 26, 2005, 9:12 pm
Access Deined event logs October 25, 2005, 8:51 am
Event ID 577 Filing Security Logs July 19, 2006, 10:45 am
RE: Who/What is sft@loader.com in our IIS Logs? MSFTPSVC Event 10 November 19, 2007, 7:38 am
RE: Who/What is sft@loader.com in our IIS Logs? MSFTPSVC Event 10 February 21, 2008, 4:20 pm
Reading Security Event Logs with Service Account November 15, 2007, 7:36 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap