[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Logparser 2.2 command line syntax.

Posted on 2007-03-20
4
Medium Priority
?
1,389 Views
Last Modified: 2012-05-05
What i need is a command line syntax using Logparser that i can use to on extracted event logs from domain controllers (.evt format), specifically parsing only the audit failures. All the .EVT files are extracted via script nightly and deposited into a network share i have access to. What i would like to do is deposit all those parsed entries of audit failures from the security logs into a .CSV file i can then look over and find anything that might be of particular interest. Ive already looked at all the different event log management tools, this is the method i am being told to use. Suggestions would be GREATLY appreciated..

Help me out and ill have your babies!
0
Comment
Question by:35armytech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 10

Accepted Solution

by:
fostejo earned 2000 total points
ID: 18784886
35armytech,

I'd suggest using the freely available Microsoft DumpEL support tool for this - it's available at http://download.microsoft.com/download/win2000platform/WebPacks/1.00.0.1/NT5/EN-US/Dumpel.exe

The following example command would list all events where the Source is 'tcpip' and the Event ID is '4201' from an Event Log backup file called 'systemlog.evt'

  dumpel -b -l systemlog.evt -e 4201 -m tcpip

By default, dumpel lists to the screen, using the -f parameter allows you to specify an output file and the -format parameter allows you to control which fields are exported.  The tool can also directly dump local or remote event logs without them having been previously exported..

cheers,
0
 

Author Comment

by:35armytech
ID: 18800006
So would this be a more effective means for dumping relevant field data to an XML file or .CSV for entry into an Access Database or Excel spreadsheet? Ive only been studying logparser since it had come so highly recommended.
0
 
LVL 10

Expert Comment

by:fostejo
ID: 18803131
35armytech,

I'd imagine so; the relevant command is above and could be simply imported into Excel ..

cheers
0
 

Author Comment

by:35armytech
ID: 18803177
Thanks, i appreciate the info.

kudos!
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use this article to create a batch file to backup a Microsoft SQL Server database to a Windows folder.  The folder can be on the local hard drive or on a network share.  This batch file will query the SQL server to get the current date & time and wi…
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
The viewer will learn the basics of jQuery, including how to invoke it on a web page. Reference your jQuery libraries: (CODE) Include your new external js/jQuery file: (CODE) Write your first lines of code to setup your site for jQuery.: (CODE)
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question