Avatar of GISCOOBY
GISCOOBYFlag for United States of America

asked on 

Looking for a comprehensive log aggregation monitor for a small Windows domain

Going through the daily logs on 12 servers is becoming too cumbersome. I working with a small domain including remote offices of about 50 users and less than 100 devices, mostly Windows clients. I looking for a way to aggregate the logs and filter for items that I need to monitor, not the entries that I know I can ignore. Small business = small budget, so my options are somewhat limited and I really don't have the time or energy to implement an enterprise class solution that requires 6 months of training just to understand. So with that said, what are your suggestions?
Windows OSNetwork AnalysisOS Security

Avatar of undefined
Last Comment
McKnife
Avatar of McKnife
McKnife
Flag of Germany image

Use scripts to filter the logs and put the output into a file that is somewhat small and readable. Powershell has commands for that (get-wineventlog). An old batch tool that you can still download is eventcomb.exe (from microsoft).
And there is also this:  https://blogs.technet.microsoft.com/otto/2008/07/08/quick-and-dirty-large-scale-eventing-for-windows/
Avatar of McKnife
McKnife
Flag of Germany image

Sorry, small correction on the powershell command: it is get-winevent
Avatar of ITguy565
ITguy565
Flag of United States of America image

There are several solutions you can use but it all depends on how indepth you want your monitoring to be.

This is the solution, I think would work best for you at the moment. It has a straight forward discovery, installation, and monitoring engine.

https://www.manageengine.com/network-monitoring/server-monitoring.html?msclkid=2bb5a40c0c191a26b863feb799c2afbe&utm_source=bing&utm_medium=cpc&utm_campaign=OpManager%20-%20Core&utm_term=server%20monitoring&utm_content=Server%20Monitoring
ASKER CERTIFIED SOLUTION
Avatar of Peter Saraby
Peter Saraby
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Dirk Kotte
Dirk Kotte
Flag of Germany image

i use splunk light as log aggregator within small lans.
Avatar of GISCOOBY
GISCOOBY
Flag of United States of America image

ASKER

I haven't dropped the question, I'm just taking my time to analyze the suggestions. So far I like the cost of PowerShell and know how to utilize it. I just know it's easy to get caught in the rabbit hole, digging deeper and deeper without finding an acceptable output I want. The Splunk Light looks nice, but when compared to EventSentry it doesn't even compare. My only issue with the EventSentry is the cost. Might be a tough sell on C-types for an event system, even though the capability can replace other products I subscribe to.
Avatar of Peter Saraby
Peter Saraby
Flag of United States of America image

I completely understand regarding PowerShell, and if you can create the report(s) that you need with it, then by all means I would go that route. But like you said, it's a potential time sink. It probably depends on whether you'll have a use for all the functionality EventSentry has included. If you do then it probably makes sense to take a closer look at it.

EventSentry's pricing is pretty fair IMHO, but that obviously depends on how much of it you'll be utilize, and what your budget looks like. If you already have similar products then why don't you ask them for competitive upgrades? I know that some vendors offer decent discounts if you switch from a competitive product. I don't know if they do, but it's worth a shot I think.
NetCrunch can handle that for you, completely remotely and without any agents. This might be the most pain-free way to do it, especially when you have several machines to monitor. Here's a KB on that: https://www.adremsoft.com/blog/view/blog/7483494443299/monitoring-text-log-files-with-netcrunch , https://www.adremsoft.com/adoc/view/netcrunch/5998261774627/monitoring-text-logs
Avatar of GISCOOBY
GISCOOBY
Flag of United States of America image

ASKER

I didn't get to fully invest my research into the solutions, especially Mariusz J.'s recommendation. Thanks everyone for your input. I gave Peter Saraby the credit because if I can wrangle his solution into the budget, that definitely they way I want to go. The Event Sentry product looks extremely comprehensive. Again, thank you everyone.
Avatar of ITguy565
ITguy565
Flag of United States of America image

Glad you found your answer!
Avatar of McKnife
McKnife
Flag of Germany image

May I ask why the free and built-in way that Microsoft has documented step by step is not suitable?
Avatar of GISCOOBY
GISCOOBY
Flag of United States of America image

ASKER

McKnife, as I mentioned in my closing statement, I love working with PowerShell; but I find that it can easily be overwhelming, especially when aggregating data. While I only have 12 servers, I can easily get overwhelmed sifting through the amount of data that is presented from them, half of which can be ignored. Again, thanks for your input, I just decided to go a different direction.
Avatar of McKnife
McKnife
Flag of Germany image

No powershell required. Please scroll again through my link https://blogs.technet.microsoft.com/otto/2008/07/08/quick-and-dirty-large-scale-eventing-for-windows/ - not a single line of powershell.
It is an understandable tutorial about the free, built-in way to collect events centrally.
Windows OS
Windows OS

This topic area includes legacy versions of Windows prior to Windows 2000: Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions including Windows Mobile.

129K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo