Solved

Method to roll off application/systems log off of server to a different volume

Posted on 2014-01-14
4
323 Views
Last Modified: 2014-03-29
Looking for automated means in Windows Server 2008 on a non-domain server to roll off the application/system logs after meeting a specific quota.  I was looking into maybe using robo copy.  Any suggestions?
0
Comment
Question by:cgooden01
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 26

Expert Comment

by:Leon Fester
ID: 39782197
This tool may be exactly what you're looking for:
http://gallery.technet.microsoft.com/Event-Log-Backup-2f5e82ec

It uses a schedule for the backups and is not based on logfile size.

I would prefer this option to ensure that you keep the files with a defined criteria and date range for easier access and troubleshooting.

The issue is that is your logs are full and there is no space then you'd have problems with the server.

The other issue is that the bigger the log files the longer it will take you to work through them when you have to find something from the archived data.
0
 

Author Comment

by:cgooden01
ID: 39788444
The above stated solution is not working for me like intended. Any other solutions out there
0
 

Accepted Solution

by:
cgooden01 earned 0 total points
ID: 39889171
This worked alot better as a batch file.

rem Script start here
rem Timestamp Generator

set BACKUP_PATH=c:\backup\

rem Parse the date (e.g., Thu 02/28/2013)
set cur_yyyy=%date:~10,4%
set cur_mm=%date:~4,2%
set cur_dd=%date:~7,2%

rem Parse the time (e.g., 11:20:56.39)
set cur_hh=%time:~0,2%
if %cur_hh% lss 10 (set cur_hh=0%time:~1,1%)
set cur_nn=%time:~3,2%
set cur_ss=%time:~6,2%
set cur_ms=%time:~9,2%

rem Set the timestamp format
set timestamp=%cur_yyyy%%cur_mm%%cur_dd%-%cur_hh%%cur_nn%%cur_ss%%cur_ms%

wevtutil epl System %BACKUP_PATH%\system_%timestamp%.evtx
wevtutil epl Application %BACKUP_PATH%\application_%timestamp%.evtx
wevtutil epl Security %BACKUP_PATH%\security_%timestamp%.evtx

rem End of Script

Step 3: Configure script in scheduler
0
 

Author Closing Comment

by:cgooden01
ID: 39963495
Solutions was great, but required modification but was accurate in its response
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question