Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 244
  • Last Modified:

Getting User logs from XP/Vista/Windows 7 - WMI queries

Hi,
We are interested in collecting user logs from Windows XP, Windows 7 and Vista.

I have briefly read about WMI queries to get this material. I don't wish to get too bogged down in coding.  I just want a tool that will make a WMI call to end users to gather the logs.

Any insight you have would be appreciated.
0
NYGiantsFan
Asked:
NYGiantsFan
2 Solutions
 
btanExec ConsultantCommented:
this can be helpful
http://blogs.sans.org/windows-security/2009/06/30/dump-windows-event-logs-to-csv-text-vbscript/

for the WMI specific codes
http://msdn.microsoft.com/en-us/library/aa394593%28v=vs.85%29.aspx

but to get it from remote computers, you will need to run it in admin right
http://msdn.microsoft.com/en-us/library/aa389290%28v=vs.85%29.aspx

or alternatively, there is a common network share which each computer will execute the vbs (WMI) or based on schedules
or alternative, having a Snare agent to get the log but then need to setup the "architecture"
@ http://www.intersectalliance.com/projects/SnareWindows/
0
 
grayeCommented:
Are you interested in how to perform this function so that you can write a program to do so....  or, are you asking for a recommendation for a free log gathering tool?

http://msdn.microsoft.com/en-us/library/bb427443(v=vs.85).aspx
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now