Solved

Getting User logs from XP/Vista/Windows 7 -  WMI queries

Posted on 2011-03-02
2
237 Views
Last Modified: 2012-05-11
Hi,
We are interested in collecting user logs from Windows XP, Windows 7 and Vista.

I have briefly read about WMI queries to get this material. I don't wish to get too bogged down in coding.  I just want a tool that will make a WMI call to end users to gather the logs.

Any insight you have would be appreciated.
0
Comment
Question by:NYGiantsFan
2 Comments
 
LVL 63

Accepted Solution

by:
btan earned 250 total points
ID: 35034155
this can be helpful
http://blogs.sans.org/windows-security/2009/06/30/dump-windows-event-logs-to-csv-text-vbscript/

for the WMI specific codes
http://msdn.microsoft.com/en-us/library/aa394593%28v=vs.85%29.aspx

but to get it from remote computers, you will need to run it in admin right
http://msdn.microsoft.com/en-us/library/aa389290%28v=vs.85%29.aspx

or alternatively, there is a common network share which each computer will execute the vbs (WMI) or based on schedules
or alternative, having a Snare agent to get the log but then need to setup the "architecture"
@ http://www.intersectalliance.com/projects/SnareWindows/
0
 
LVL 41

Assisted Solution

by:graye
graye earned 250 total points
ID: 35109500
Are you interested in how to perform this function so that you can write a program to do so....  or, are you asking for a recommendation for a free log gathering tool?

http://msdn.microsoft.com/en-us/library/bb427443(v=vs.85).aspx
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OnPage: Incident management and secure messaging on your smartphone
Do you know what to look for when considering cloud computing? Should you hire someone or try to do it yourself? I'll be covering these questions and looking at the best options for you and your business.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question