I have several servers I manage and unfortunately, fall under S.O.X. Auditing.
I don't like having to go into every server once a month and crab the log files from the Event Viewer and store them over in our evidence area. My thought is to have the Event items sent directly to a SYSLOG server which has centralized storage and which we are using for our Firewall, routers, switches and various other devices.
I would think I could send all them to the syslog and then have them sorted and/or filtered by event type/id and only have to take a look at it once a month or so to make sure everything is alright and address any problems.
So, the question would be, does this make sense and / or how to I pass these events onto a SYSLOG server?
Start Free Trial