• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1463
  • Last Modified:

Search Multiple Event Log Files

I am saving my file share audit log files in 20 MB increments to a share.  They are .EVT format (classic windows event log).  I can easily convert them to .EVTX, but I occasionally need to search 4 days worth of logs for a specific entry.  I really have no easy method of searching 100 .EVT or .EVTX files for a specific entry.  Any help would be greatly appreciated.
0
BDizzle
Asked:
BDizzle
  • 2
  • 2
  • 2
1 Solution
 
Seaton007Commented:
0
 
Steve KnightIT ConsultancyCommented:
Have you looked at logparser?

http://www.microsoft.com/en-us/download/details.aspx?id=24659

You should be able to use a for loop to run it against multiple, e.g. something like this (sorry not got to hand to test at the mo.)

Steve

@echo off
cd /d "C:\root\of\evt area"
for /f "tokens=*" %%f in ('dir /b /a-d /s *.evt') do (
 echo Looking at %%f
" c:\program files\log parser 2.2\logparser" -c -i:EVT -o:TEXLINE "%%~f" output.csv
)
0
 
Steve KnightIT ConsultancyCommented:
and build your query into logparser command, or export the lot to CSV or whatever and search that.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
Seaton007Commented:
0
 
BDizzleAuthor Commented:
I had tried event eventlog parser with no success.  I probably had the syntax wrong...  I will look at some of those tools listed.
0
 
BDizzleAuthor Commented:
Installed splunk, and indexed within 20 minutes.  Found what I needed right away!  Thanks!
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 2
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now