Member_2_6492660_1
asked on
Logparser 2.2 against Exchange 2010 RCA Logs
Exchange Server 2010 SP3 RU 8 Enterprise 64 Bit
Logparser 2.2
Windows 2008 R2 Server 64bit
Results fail
C:\Util>clientip
C:\Util>rem @echo off
C:\Util>del clientip.txt
C:\Util>"C:\Program Files (x86)\Log Parser 2.2\logparser.exe" "SELECT Extract_Su
ffix(client-name,0,'=') as User,client-name as DN,client-software,client- softwar
e-version as Version,client-mode,client -ip,protoc ol from D:\Progra~1\Microsoft\E
xchan~1\V14\Logging\RPC Client Access\RCA*.log WHERE (operation='Connect') GROUP
BY User,DN,client-software,Ve rsion,clie nt-mode,cl ient-ip,pr otocol ORDER BY User
" -i:CSV -nSkipLines:4 -o:CSV 1>c:\util\clientIp.txt
Error: Syntax Error: extra token(s) after query: 'Client'
C:\Util>cd\util
C:\Util>Pause
Press any key to continue . . .
Terminate batch job (Y/N)? y
C:\Util>
Is my code correct?
Thoughts?
Logparser 2.2
Windows 2008 R2 Server 64bit
rem @echo off
del clientip.txt
"C:\Program Files (x86)\Log Parser 2.2\logparser.exe" "SELECT Extract_Suffix(client-name,0,'=') as User,client-name as DN,client-software,client-software-version as Version,client-mode,client-ip,protocol from D:\Progra~1\Microsoft\Exchan~1\V14\Logging\RPC Client Access\RCA*.log WHERE (operation='Connect') GROUP BY User,DN,client-software,Version,client-mode,client-ip,protocol ORDER BY User" -i:CSV -nSkipLines:4 -o:CSV >c:\util\clientIp.txt
Results fail
C:\Util>clientip
C:\Util>rem @echo off
C:\Util>del clientip.txt
C:\Util>"C:\Program Files (x86)\Log Parser 2.2\logparser.exe" "SELECT Extract_Su
ffix(client-name,0,'=') as User,client-name as DN,client-software,client-
e-version as Version,client-mode,client
xchan~1\V14\Logging\RPC Client Access\RCA*.log WHERE (operation='Connect') GROUP
BY User,DN,client-software,Ve
" -i:CSV -nSkipLines:4 -o:CSV 1>c:\util\clientIp.txt
Error: Syntax Error: extra token(s) after query: 'Client'
C:\Util>cd\util
C:\Util>Pause
Press any key to continue . . .
Terminate batch job (Y/N)? y
C:\Util>
Is my code correct?
Thoughts?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi
Any thoughts on this?
Any thoughts on this?
As I mentioned, try a reduced version to track down this cause. Maybe something like:
"SELECT * from D:\Progra~1\Microsoft\Exch an~1\V14\L ogging\RPC Client Access\RCA*.log" -i:CSV -nSkipLines:4 -o:CSV
If that works, build up:
"SELECT Extract_Suffix(client-name ,0,'=') as User from D:\Progra~1\Microsoft\Exch an~1\V14\L ogging\RPC Client Access\RCA*.log" -i:CSV -nSkipLines:4 -o:CSV
Etc...
"SELECT * from D:\Progra~1\Microsoft\Exch
If that works, build up:
"SELECT Extract_Suffix(client-name
Etc...
ASKER
NewVillageIT
I figured it out It was
Had to change
D:\Progra~1\Microsoft\Exch an~1\V14\L ogging\RPC Client Access\RCA*.log
To
'D:\Program Files\Microsoft\Exchange Server\V14\Logging\RPC Client Access\RCA*.log'
Now it runs
I figured it out It was
@echo off
del clientip.txt
"C:\Program Files (x86)\Log Parser 2.2\logparser.exe" "SELECT Extract_Suffix(client-name,0,'=') as User,client-name as DN,client-software,client-software-version as Version,client-mode,client-ip,protocol from 'D:\Program Files\Microsoft\Exchange Server\V14\Logging\RPC Client Access\RCA*.log' WHERE (operation='Connect') GROUP BY User,DN,client-software,Version,client-mode,client-ip,protocol ORDER BY User" -i:CSV -nSkipLines:4 -o:CSV >c:\util\clientIp.txt
cd\util
Had to change
D:\Progra~1\Microsoft\Exch
To
'D:\Program Files\Microsoft\Exchange Server\V14\Logging\RPC Client Access\RCA*.log'
Now it runs
Awesome! Glad you got it working...
ASKER
That lead me to the solution.
Just needed a little time to look over the code.
Thanks for your help
You have any knowledge about receive connectors?
I have an open questions on that subject if you can help with that one here it is
https://www.experts-exchange.com/questions/28609455/ReceiveConnectors-on-Exchange-2010-Help-needed.html
Thanks again
Just needed a little time to look over the code.
Thanks for your help
You have any knowledge about receive connectors?
I have an open questions on that subject if you can help with that one here it is
https://www.experts-exchange.com/questions/28609455/ReceiveConnectors-on-Exchange-2010-Help-needed.html
Thanks again
ASKER
on Exchange 2007 you got this information from this command
get-logonstatistics myuser | sort-object clientipaddress | format-table username,clientipaddress,l
Now on Exchange 2010 that does not exist so I am trying to replicate the same report using logparser
DIR /X D:\Progra~1\Microsoft\Exch
RPC Client Access