Solved

Getting Read/Write data on files in command line or output into a file -- windows server 2008

Posted on 2011-09-21
4
256 Views
Last Modified: 2012-05-12
Hello, I use Windows Server 2008:

I ultimately just want to have a file with the following data in it:
1) A list of files being written to or read from(with the full path like C:\folder\filename.txt -- this is *important*)
2) How much it is being written to or read from every minute or second or hour

So if there is a command line way of doing this, I can output it into a file. I've searched high and low and haven't found a solution so any help is greatly appreciated.
0
Comment
Question by:weblocked
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 4

Expert Comment

by:Felicia King
ID: 36577840
Can't you turn on file auditing for that folder and then use an event log parser to get the information you are looking for? I did this about 10 years ago and that's what I did. I used Event Comb MT for event log parsing and capture. Not sure if it's around anymore. Was a free Microsoft utility.
0
 

Author Comment

by:weblocked
ID: 36578392
Thanks locojalapeno -- can you elaborate more? I'm not familiar with file auditing or event log parsers. Also, the server is already tracking this information it appears since perfmon shows this in the Resources boxes when you bring up perfmon. I basically want what is underneath the "Disk" section of it, it lists the file path and the read and write to the file. Please note I want the entire server, not just specific folders.
0
 
LVL 4

Accepted Solution

by:
Felicia King earned 500 total points
ID: 36579976
This link http://www.techotopia.com/index.php/Auditing_Windows_Server_2008_File_and_Folder_Access
has a pretty decent description of how to turn on file auditing in Windows server. There are other articles out there too you can lookup if you need more detail. That basically gets the stuff into your event log. Make sure you crank up the settings on your event log. I usually set policy for overwrite as needed and have an event log that is at least 100 MB.

Then you have to get the info out of the logs. The ideal situation is if you had Kaseya. You could write a monitoring set that would specifically look for a set of events and report those back to you. If you don't have Kaseya, do you have some other monitoring tool like MOM that could do the same thing? That's how you are going to get automation. However, if you don't have those, and you want to manually fiddle, you need EventComb MT. Frankly, any event log parser tool will do.
http://support.microsoft.com/kb/824209
Above is an article I found on EventComb MT.
I have a modified version Jeff Lambert at Microsoft wrote for me in 2003. He tweaked it for multi-processor throttling and efficiency. He is brillliant.

Once you have the event logs in a parsed format (seeing only the events you want from the servers you want), you have to read them manually.

I have used NetIQ as well as MOM and Kaseya for automating the grabbing of particular events as they show up on a server and reporting on them.

Regarding your comment about the entire server, it's my understanding that exact file/folder auditing has to be enabled on each share manually. If you did that already, great.
Below is another interesting article on the subject.
http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/9e633bad-cda6-4ec4-8f04-c01de57ce767
0
 

Author Closing Comment

by:weblocked
ID: 37097561
Close enough -- I can't really use this though due its large complexity of deploying on over 100 servers and the overhead required to manage it properly. There should be a simple way for me to get the file output/input, etc, perfmon already does it.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question