Solved

Event Viewer Parser

Posted on 2004-04-15
7
774 Views
Last Modified: 2012-06-21
Hello EE,
Ive looked around the net for a good tool to parse logs from the windows event viewer. I found a good one called Event Log View that does what I want...I just would like a free utility for this if there is one that is comparable. I work for a non-profit agency, so dont think Im just being cheap...its for good reason that I use free tools. If anyone out there knows of a tool that will allow me to view, filter, report and manage the event logs on my servers, and that is free, or very reasonablely priced...please let me know.

Thanks
Joe
0
Comment
Question by:JoeDW
7 Comments
 
LVL 11

Expert Comment

by:ewtaylor
ID: 10836521
Well you could save as a comma delimited and import it into excel.
0
 
LVL 1

Author Comment

by:JoeDW
ID: 10836556
Yes, but the whole idea for such a tool is to minimize the manual part of looking through the event viewer for issues and such. We have about 20 servers here...and every day the logs get cleared out by me. A tool to let me parse them and check whats going on from my workstation would be very helpful and less time consuming.

Thanks again
0
 
LVL 15

Expert Comment

by:sr75
ID: 10837194
why not your machine's event viewer?  It allows for what you want to do.

Action - Open Log file should allow you to view it and then Filter it so that you can see the errors and such that you want to see.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 83

Expert Comment

by:oBdA
ID: 10837238
Maybe I'm stating the obvious here, but it might be that you just missed out on this. The cheapest and easiest solution comes with your OS: You can simply create a dedicated MMC that has the event logs of all your servers available without you having manually to connect to everyone.
From the "run" menu on your workstation, start "MMC".
In the "Console" menu, choose "Add/Delete Snap-in",
Click the "Add" button, choose "Event Viewer". In the next window, enter the name of the server. Repeat until you have listed all your servers.
From the Console menu, save the new console someplace and create a shortcut to it.
When you do a right-click on the logs, you have a filtering and a search function as well.

Depending on what you want to do, you could check out logparser, a free tool from Microsoft that lets you run queries against an event log.
Log Parser
http://www.microsoft.com/downloads/details.aspx?displaylang=en&familyid=8cde4028-e247-45be-bab9-ac851fc166a4
0
 
LVL 41

Accepted Solution

by:
graye earned 50 total points
ID: 10837851
If you're interested in collecting more than just the event logs, I've got a free program that will collect 182 pieces of information from each server (including the event log, obviously) and store it in a central database.   We run it as a scheduled task, so that it keep the database up-to-date.  That way you can create custom queries to search for whatever you like.

The program is called SOSOS, and will collect all sorts of things like, installed software, BIOS rev levels, Microsoft update patches, CPU, disk space, etc, etc, etc.

My FTP server is down for a while (usually it'd be available via ftp://ftp.dpw.hood.army.mil), but I also maintain it at http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=364&lngWId=10 (in VB.Net source code format only... no executable, sorry)
0
 
LVL 1

Author Comment

by:JoeDW
ID: 10841698
Sorry if Im not being clear enough, and thanks for the comments they are most helpful... I understand that the event viewer on the OS is the best way, but going to 20 different servers, reading through and clearing the logs is a time consuming task...I want a simple app that lets me do this from the workstation im at...i know MMC does this but I also need filtering and rules...the app I mentioned above is about the closest thing I can think of and the cheapest too. Unless anyone knows of an app that does this for a cheaper price? and Graye....I will check out your code and let you know...thanks
0
 
LVL 11

Expert Comment

by:ewtaylor
ID: 10842058
Ok how about just writing a small batch file that uses the dumpel command http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/dumpel-o.asp
or even the elogdmp command
http://www.tburke.net/info/reskittools/topics/elogdmp.htm
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this article, I show you step by step with screenshots to assist you - HOW TO: Deploy and Install the VMware vCenter Server Appliance 6.5 (VCSA 6.5), with some helpful tips along the way.
This video discusses moving either the default database or any database to a new volume.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now