[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Getting Read/Write data on files in command line or output into a file -- windows server 2008

Posted on 2011-09-21
4
Medium Priority
?
264 Views
Last Modified: 2012-05-12
Hello, I use Windows Server 2008:

I ultimately just want to have a file with the following data in it:
1) A list of files being written to or read from(with the full path like C:\folder\filename.txt -- this is *important*)
2) How much it is being written to or read from every minute or second or hour

So if there is a command line way of doing this, I can output it into a file. I've searched high and low and haven't found a solution so any help is greatly appreciated.
0
Comment
Question by:weblocked
  • 2
  • 2
4 Comments
 
LVL 4

Expert Comment

by:Felicia King
ID: 36577840
Can't you turn on file auditing for that folder and then use an event log parser to get the information you are looking for? I did this about 10 years ago and that's what I did. I used Event Comb MT for event log parsing and capture. Not sure if it's around anymore. Was a free Microsoft utility.
0
 

Author Comment

by:weblocked
ID: 36578392
Thanks locojalapeno -- can you elaborate more? I'm not familiar with file auditing or event log parsers. Also, the server is already tracking this information it appears since perfmon shows this in the Resources boxes when you bring up perfmon. I basically want what is underneath the "Disk" section of it, it lists the file path and the read and write to the file. Please note I want the entire server, not just specific folders.
0
 
LVL 4

Accepted Solution

by:
Felicia King earned 1500 total points
ID: 36579976
This link http://www.techotopia.com/index.php/Auditing_Windows_Server_2008_File_and_Folder_Access
has a pretty decent description of how to turn on file auditing in Windows server. There are other articles out there too you can lookup if you need more detail. That basically gets the stuff into your event log. Make sure you crank up the settings on your event log. I usually set policy for overwrite as needed and have an event log that is at least 100 MB.

Then you have to get the info out of the logs. The ideal situation is if you had Kaseya. You could write a monitoring set that would specifically look for a set of events and report those back to you. If you don't have Kaseya, do you have some other monitoring tool like MOM that could do the same thing? That's how you are going to get automation. However, if you don't have those, and you want to manually fiddle, you need EventComb MT. Frankly, any event log parser tool will do.
http://support.microsoft.com/kb/824209
Above is an article I found on EventComb MT.
I have a modified version Jeff Lambert at Microsoft wrote for me in 2003. He tweaked it for multi-processor throttling and efficiency. He is brillliant.

Once you have the event logs in a parsed format (seeing only the events you want from the servers you want), you have to read them manually.

I have used NetIQ as well as MOM and Kaseya for automating the grabbing of particular events as they show up on a server and reporting on them.

Regarding your comment about the entire server, it's my understanding that exact file/folder auditing has to be enabled on each share manually. If you did that already, great.
Below is another interesting article on the subject.
http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/9e633bad-cda6-4ec4-8f04-c01de57ce767
0
 

Author Closing Comment

by:weblocked
ID: 37097561
Close enough -- I can't really use this though due its large complexity of deploying on over 100 servers and the overhead required to manage it properly. There should be a simple way for me to get the file output/input, etc, perfmon already does it.
0

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Suggested Courses

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question