Solved

Getting User logs from XP/Vista/Windows 7 -  WMI queries

Posted on 2011-03-02
2
230 Views
Last Modified: 2012-05-11
Hi,
We are interested in collecting user logs from Windows XP, Windows 7 and Vista.

I have briefly read about WMI queries to get this material. I don't wish to get too bogged down in coding.  I just want a tool that will make a WMI call to end users to gather the logs.

Any insight you have would be appreciated.
0
Comment
Question by:NYGiantsFan
2 Comments
 
LVL 61

Accepted Solution

by:
btan earned 250 total points
ID: 35034155
this can be helpful
http://blogs.sans.org/windows-security/2009/06/30/dump-windows-event-logs-to-csv-text-vbscript/

for the WMI specific codes
http://msdn.microsoft.com/en-us/library/aa394593%28v=vs.85%29.aspx

but to get it from remote computers, you will need to run it in admin right
http://msdn.microsoft.com/en-us/library/aa389290%28v=vs.85%29.aspx

or alternatively, there is a common network share which each computer will execute the vbs (WMI) or based on schedules
or alternative, having a Snare agent to get the log but then need to setup the "architecture"
@ http://www.intersectalliance.com/projects/SnareWindows/
0
 
LVL 41

Assisted Solution

by:graye
graye earned 250 total points
ID: 35109500
Are you interested in how to perform this function so that you can write a program to do so....  or, are you asking for a recommendation for a free log gathering tool?

http://msdn.microsoft.com/en-us/library/bb427443(v=vs.85).aspx
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Healthcare organizations in the United States must adhere to the guidance of both the HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) for securing and protec…
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now