Forefront - central change tracking

How can I export the Change Tracking logs from Forefront TMG 2010 in to Splunk?
LVL 1
timbrighamAsked:
Who is Participating?
 
timbrighamConnect With a Mentor Author Commented:
We developed an in house solution.
0
 
Keith AlabasterEnterprise ArchitectCommented:
Wow - and you want our help asking like that?
0
 
timbrighamAuthor Commented:
Fair enough. I was hoping a canned solution (script, 3rd party log parser, etc) was available and I simply hadn't come across it. I didn't think off host storage of audit logs was that unusual of a desire.

I'm familiar with how the data is stored in the registry and some options for scripting the content into an XML file. If I really had to I could get something set up that periodically parses the XML, performs a diff against an old version of the file to find new events and shoots the diff to a text file to be imported via a generic agent.

That just seems a horribly clunky solution to what I thought would be an easy task; is there any easier way to address this?
0
 
timbrighamAuthor Commented:
Developed in house solution.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.