Re: [logs] Retrieving logs from Windows server

From: Harlan Carvey (keydet89@private)
Date: Mon Jan 24 2005 - 10:23:02 PST

> The last option is
> exactly what I am looking for. 

Okay.  It wasn't clear, but I thought I'd just throw
it in.

> I have a central Syslog server on my Linux machine
> and
> I wish to send my Windows Server logs to it for
> collection. Maybe I missed something, but I didn't
> see
> any option to have Windows Server act as a Syslog
> client? 

New to Windows, eh?  ;-)  Windows is billed as a
"network operating system", yet doesn't have a native,
default-install capability for central log management.
 There are add-ons, from third parties, as well as
Microsoft itself.  One is called EventComb, but that
only works with the Security Event Log.  

I believe that MS's official standing is "we don't
need no stinkin' syslog".  ;-)

> Could you point me towards a reference?

Sure: Google

Harlan Carvey, CISSP
"Windows Forensics and Incident Recovery"
LogAnalysis mailing list

This archive was generated by hypermail 2.1.3 : Mon Jan 24 2005 - 10:32:12 PST