Solved

Can Ntbackup and 2008 backup, backup and restore windows event logs?

Posted on 2009-07-15
3
607 Views
Last Modified: 2012-06-27
Hi,

Could someone show me official Microsoft documentation that shows whether or not Windows 2003 ntbackup (or 2008 backup) is able to backup and restore Windows event log files.

I know that if you try and backup the .evt files directly (C:\WINDOWS\system32\config) that ntbackup will silently skip out those files. By 'silently' I mean the backup will show as being 100% successful, and no event logs will be backed up, or reported as not being able to be backed up.

The contents of system state is described here:
http://technet.microsoft.com/en-us/library/cc785306%28WS.10%29.aspx

I have not investigated 2008 backup capabilities, but if you happen to know event log backup on 2008 that would be useful.

*Note* I know that there are WMI scripts to backup eventlogs. This is not what I am asking. I am asking whether the built in backup software can do it.

Thank you for your time.


0
Comment
Question by:harrowc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 2

Expert Comment

by:cj52973
ID: 24880629
That's expected behavior if you run the process with a non-administrative account.
To backup the EVT logs the user (or worker process) needs to have Admin rights to the machine.
0
 
LVL 3

Author Comment

by:harrowc
ID: 24885046
You are incorrect.
Even admins cannot backup these files.
Try it for yourself.

0
 
LVL 3

Accepted Solution

by:
harrowc earned 0 total points
ID: 24891615
To test the 2003 backup side of things I performed the following steps:

1. On 2003 DC, backed up system state using ntbackup.
2. Cleared event logs.
3. Rebooted into Active Directory Restore mode
4. Used ntbackup to restore the system state
5. Rebooted into normal mode
6. Event viewer showed no events older than when I cleared the event logs in step 2.

This practical experiment answers one of my questions:

Does 2003 system state backup, backup the Windows event logs?
Answer: No.

Does anyone know if 2008 is the same?

0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question