Solved

Logparser 2.2 command line syntax.

Posted on 2007-03-20
4
1,368 Views
Last Modified: 2012-05-05
What i need is a command line syntax using Logparser that i can use to on extracted event logs from domain controllers (.evt format), specifically parsing only the audit failures. All the .EVT files are extracted via script nightly and deposited into a network share i have access to. What i would like to do is deposit all those parsed entries of audit failures from the security logs into a .CSV file i can then look over and find anything that might be of particular interest. Ive already looked at all the different event log management tools, this is the method i am being told to use. Suggestions would be GREATLY appreciated..

Help me out and ill have your babies!
0
Comment
Question by:35armytech
  • 2
  • 2
4 Comments
 
LVL 10

Accepted Solution

by:
fostejo earned 500 total points
ID: 18784886
35armytech,

I'd suggest using the freely available Microsoft DumpEL support tool for this - it's available at http://download.microsoft.com/download/win2000platform/WebPacks/1.00.0.1/NT5/EN-US/Dumpel.exe

The following example command would list all events where the Source is 'tcpip' and the Event ID is '4201' from an Event Log backup file called 'systemlog.evt'

  dumpel -b -l systemlog.evt -e 4201 -m tcpip

By default, dumpel lists to the screen, using the -f parameter allows you to specify an output file and the -format parameter allows you to control which fields are exported.  The tool can also directly dump local or remote event logs without them having been previously exported..

cheers,
0
 

Author Comment

by:35armytech
ID: 18800006
So would this be a more effective means for dumping relevant field data to an XML file or .CSV for entry into an Access Database or Excel spreadsheet? Ive only been studying logparser since it had come so highly recommended.
0
 
LVL 10

Expert Comment

by:fostejo
ID: 18803131
35armytech,

I'd imagine so; the relevant command is above and could be simply imported into Excel ..

cheers
0
 

Author Comment

by:35armytech
ID: 18803177
Thanks, i appreciate the info.

kudos!
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Not long ago I saw a question in the VB Script forum that I thought would not take much time. You can read that question (Question ID  (http://www.experts-exchange.com/Programming/Languages/Visual_Basic/VB_Script/Q_28455246.html)28455246) Here (http…
Active Directory replication delay is the cause to many problems.  Here is a super easy script to force Active Directory replication to all sites with by using an elevated PowerShell command prompt, and a tool to verify your changes.
The viewer will learn the basics of jQuery, including how to invoke it on a web page. Reference your jQuery libraries: (CODE) Include your new external js/jQuery file: (CODE) Write your first lines of code to setup your site for jQuery.: (CODE)
In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question