Solved

Read partly corrupted Event Logfile

Posted on 2004-09-13
8
218 Views
Last Modified: 2010-04-14
Hi, my RAID array failed for an unknown reason: http://www.experts-exchange.com/Storage/Q_21126972.html

I have been able to partly recover the 3 event log files, they are partly corrupted, contain some unencrypted text but is also encrypted or something by the event viewer.

I know that if I load them into the Windows 2000 event viewer it will just tell me that the files are corrupted... So how can I read these files?

I'm hoping they will give me a clue to why my array failed...
0
Comment
Question by:Occupied
  • 4
  • 4
8 Comments
 
LVL 67

Accepted Solution

by:
sirbounty earned 500 total points
Comment Utility
0
 
LVL 1

Author Comment

by:Occupied
Comment Utility
Eldump was unable to do anything, it gave me the message that the logfile was corrupted, I'm guessing it used the Windows driver to look at the file because it gave me the error message in Swedish... (my system is Swedish..)

PsLogList gave me the same error message as ElDump...

Dumpel did not seem to have any option to read from a local file...
0
 
LVL 67

Expert Comment

by:sirbounty
Comment Utility
Hmm - let me take a look at your original question...brb.
0
 
LVL 67

Expert Comment

by:sirbounty
Comment Utility
So how were you able to recover the evt files?  I can't see the image from here (blocked by company proxy).
Doesn't sound good to me though.  Have you tried restorer 2000 by chance?
( http:Q_21014635.html#11240391)

Only other thing I could think is maybe a rom-based log?  Not familiar with your system - so not sure if that's even an option -but if psloglist won't view it, I don't know what will.  Sorry my friend.
Best of luck to you!
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 1

Author Comment

by:Occupied
Comment Utility
Since my other harddrive in the RAID array lost it's data I have the odd chunks of 32kb from the event viewer files (the even parts was of course on the other harddrive...)... Hence the corruption..

My system is just a desktop computer, the logfile was only saved on the harddrives...
0
 
LVL 1

Author Comment

by:Occupied
Comment Utility
If no one is able to help me with this how do I close this question? (I'm new to EE...)
0
 
LVL 67

Expert Comment

by:sirbounty
Comment Utility
Since I'm the only respondant, I can delete/refund if you like.
For future reference:
  See http:help.jsp#hs5
0
 
LVL 1

Author Comment

by:Occupied
Comment Utility
To have it deleted would be a waste, I'm rewarding you the points because those applications might become useful to me in the future and you took the time to try any answer my question.
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now