Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Re: Server 2003 - Creating a single folder security log

Reply
Thread Tools Display Modes

Re: Server 2003 - Creating a single folder security log

 
 
RCan
Guest
Posts: n/a

 
      05-18-2010
Hi JR,

of course :-)

a.e. if you monitor the systems a.e. with SCOM you can collect the events
and write them into a database for an history purpose.
a.e. only for this SCOM is not a "must" criteria, you can also write a own
script where you export the eventlog to a.e. etl/html/xml file and then
reset after a succesfull export ;-)

In W2K8 systems you could also use "wevtutil.exe" but I could not remember
currently an command line based tool for W2K3. In any case you can also use
the public available eventlog API's a.e. with "ClearEventLog Function" ->
http://msdn.microsoft.com/en-us/library/aa363637.aspx ;-)
http://tekktips.spaces.live.com/blog...04D7!463.entry

Also in most cases and especially in security area you will log too much
information's which is not really useful, check also each enabled setting,
if really required, some of them can make a big difference.

PS : AND thereare several 3rd party tools available which does exactly this
:-)

Hope that helps

Regards
Ramazan

"JR" <> wrote in message
news:...
> Hia folks
>
>
> I'm trying to solve a tough (for me) security problem. I have to set
> up a series of restricted access folders in our network. The users
> insist in keep a log of all access to these folders. Fair enough, but
> my problem is that the "securty log" on the event viewer is allready
> extended to the maximum size, and it can't keep log entrances older
> than 7 days (no room in log...)
>
> I'd like to know if there are tools, or settings (whetever) that would
> allow me to set up extra log files just for these folders. I'd then be
> abble to keep them for a lot longer than those 7 days of the standard
> log.


 
Reply With Quote
 
 
 
 
RCan
Guest
Posts: n/a

 
      05-20-2010
Correct, then a.e. you could also create an database and import the data.
afterwards you can query anything and in any combination .... :-)
Also reporting services on top of your DB could be an useful "feature" if
you want to have a longterm history of your security logs and reports can be
generated on demand.

Note : be also careful with logging user activity as this is most europe
countries in some circumstances not allowed !

Hope that helps

Regards
Ramazan
http://tekktips.spaces.live.com/default.aspx

"JR" <> wrote in message
news:...
> On Tue, 18 May 2010 21:18:18 +0200, "RCan" <> wrote:
>
>>Hi JR,
>>
>>of course :-)
>>
>>a.e. if you monitor the systems a.e. with SCOM you can collect the events
>>and write them into a database for an history purpose.
>>a.e. only for this SCOM is not a "must" criteria, you can also write a own
>>script where you export the eventlog to a.e. etl/html/xml file and then
>>reset after a succesfull export ;-)
>>
>>In W2K8 systems you could also use "wevtutil.exe" but I could not remember
>>currently an command line based tool for W2K3. In any case you can also
>>use
>>the public available eventlog API's a.e. with "ClearEventLog Function" ->
>>http://msdn.microsoft.com/en-us/library/aa363637.aspx ;-)
>>http://tekktips.spaces.live.com/blog...04D7!463.entry
>>
>>Also in most cases and especially in security area you will log too much
>>information's which is not really useful, check also each enabled setting,
>>if really required, some of them can make a big difference.
>>
>>PS : AND thereare several 3rd party tools available which does exactly
>>this
>>:-)
>>
>>Hope that helps
>>
>>Regards
>>Ramazan

>
> If I understand you correctly, what you propose is to simply save
> copies of the normal log over time, and then search it for the
> relevant data?


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What's wrong with my live.com account? Michael Elliott Windows Live Mail 43 1 Week Ago 09:36 PM
Re: Windows 2003 DNS and AD problems Danny Sanders DNS Server 0 03-30-2010 08:34 PM
17 repeatedly offered updates not installing Cheshire Windows Update 2 02-28-2010 04:59 AM
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM
The local domain controller could not connect with - 2008 boe Active Directory 9 11-22-2009 01:05 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59