Utilities/programs that analyze event viewer logs

What are some good utilities or programs that analyze event viewer logs (such as the system and application logs) to discover trends and provide detailed explanations of what the different events mean?
IT GuyNetwork EngineerAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
NVITEnd-user supportCommented:
Netwrix Auditor for Active Directory

Enterprise diagram provides a high-level overview of activity trends by date, user, server, object type or
data source in your IT infrastructure. The Enterprise diagram aggregates data on all monitoring plans and all data sources, while system-specific diagrams provide quick access to important statistics within one data source.

https://www.netwrix.com/download/QuickStart/Netwrix_Auditor_for_Active_Directory_Quick_Start_Guide.pdf
0
Peter SarabySenior IT ProCommented:
I've never heard or seen of "EvLog" anywhere, this is definitely not a product that's widely in use as far as I know. The site eventid.net itself has been around for a while and does have a good database for events, but I wouldn't use their software.

GFI's event manager is a dead product that hasn't been updated in years. The latest update (after years of silence) only addressed bugs and added support for newer Microsoft Operating Systems.

Netwrix's strengths lie elsewhere, I wouldn't use them for event log monitoring.

ManageEngine is somewhat common, but their products often have an insecure design, partially because they don't use agents. It's an entry level product I wouldn't really recommend. SolarWinds has a product but it's overpriced and not worth the money IMHO.

If you're looking for something free then I would suggest Graylog, although it won't provide descriptions of events and is difficult to deploy and maintain. To be honest, most products don't have embedded explanations and you're better off searching Google for specific events you encounter. Even if a product would have some explanations, it wouldn't trust it to be complete.

I've had good results with EventSentry, it's very strong on the Windows side and reasonably priced. I believe it does make it easy to search Google once you get or view an alert from it.
0
Ajit SinghCommented:
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 10

From novice to tech pro — start learning today.