[logs] Re: Microsoft Event ID

From: James Turnbull (james@private)
Date: Thu Mar 16 2006 - 15:19:28 PST


Salvati Amedeo wrote:
> Hi all,
>
> i'm working with a commercial product who parse all event from domain controllers (i think they are 60) but now, my problem is correlate this (on real-time), and search on our db (for auditing and reports). My questions is: someone know|have a list of very important EventID for Security microsoft windows, on special case windows 2003?
>
> thanks
> amedeo
>   
Have a look at the following sites:

http://www.ultimatewindowssecurity.com/encyclopedia.html
http://www.eventid.net/

And obviously the Microsoft sites have a wealth of information.

Regards

James Turnbull

-- 
James Turnbull <james@private>
---
Author of Pro Nagios 2.0
(http://www.amazon.com/gp/product/1590596099/)

Hardening Linux
(http://www.amazon.com/gp/product/1590594444/)
---
PGP Key (http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x0C42DF40)


_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Thu Mar 16 2006 - 15:21:12 PST