Re: [logs] Retrieving logs from Windows server

From: Harlan Carvey (keydet89@private)
Date: Mon Jan 24 2005 - 10:23:02 PST


> The last option is
> exactly what I am looking for. 

Okay.  It wasn't clear, but I thought I'd just throw
it in.

> I have a central Syslog server on my Linux machine
> and
> I wish to send my Windows Server logs to it for
> collection. Maybe I missed something, but I didn't
> see
> any option to have Windows Server act as a Syslog
> client? 

New to Windows, eh?  ;-)  Windows is billed as a
"network operating system", yet doesn't have a native,
default-install capability for central log management.
 There are add-ons, from third parties, as well as
Microsoft itself.  One is called EventComb, but that
only works with the Security Event Log.  

I believe that MS's official standing is "we don't
need no stinkin' syslog".  ;-)

> Could you point me towards a reference?

Sure: Google
http://www.google.com/search?hl=en&q=Windows+%2B+%22syslog+client%22




=====
------------------------------------------
Harlan Carvey, CISSP
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com
http://windowsir.blogspot.com
------------------------------------------
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Mon Jan 24 2005 - 10:32:12 PST