Looking at windows logs
"James B Horwath" <[email protected]> Thu, 29 May 2008 08:42:36 -0400
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <OF2A512BCF.0530C525-ON85257458.0038B2FE-85257458.0045D153@glic.com> |
This is a multi-part message in MIME format. --===============1308112039== Content-Transfer-Encoding: 7bit Content-Class: urn:content-classes:message Content-Type: multipart/alternative; boundary="=_alternative 0045D15285257458_=" This is a multi-part message in MIME format. --=_alternative 0045D15285257458_= Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit I hope somebody can help me. I have a windows EVT file from a system that I want to view on another computer (which is a windows XP laptop). I booted the laptop with Linux (backtrack) and tried to remove the old security.evt file and replace it with mine. Even with the windows drive mounted with "rw" I could manipulate any of the files or permissions. I kept receiving a message "read-only" media. I thought maybe I could use the eventquery.vbs file from the command line using the /L switch to dump the logs, this did not work. It appears only the windows categories are readable. I have a licensed copy of Adiscon eventviewer and a copy of lasso. Can anyone offer any suggestions on how to extract this data? Thanks in advance. Jim ----------------------------------------- This message, and any attachments to it, may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, you are notified that any use, dissemination, distribution, copying, or communication of this message is strictly prohibited. If you have received this message in error, please notify the sender immediately by return e-mail and delete the message and any attachments. Thank you. --=_alternative 0045D15285257458_= Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: 7bit <br><font size=2 face="sans-serif"><br> I hope somebody can help me. I have a windows EVT file from a system that I want to view on another computer (which is a windows XP laptop). I booted the laptop with Linux (backtrack) and tried to remove the old security.evt file and replace it with mine. Even with the windows drive mounted with "rw" I could manipulate any of the files or permissions. I kept receiving a message "read-only" media.</font> <br> <br><font size=2 face="sans-serif">I thought maybe I could use the eventquery.vbs file from the command line using the /L switch to dump the logs, this did not work. It appears only the windows categories are readable. I have a licensed copy of Adiscon eventviewer and a copy of lasso. </font> <br> <br><font size=2 face="sans-serif">Can anyone offer any suggestions on how to extract this data?</font> <br> <br><font size=2 face="sans-serif">Thanks in advance.</font> <br><font size=2 face="sans-serif">Jim</font> <br> <br><font size=2 face="sans-serif"> </font> <P><hr size=1></P> <P><STRONG> This message, and any attachments to it, may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, you are notified that any use, dissemination, distribution, copying, or communication of this message is strictly prohibited. If you have received this message in error, please notify the sender immediately by return e-mail and delete the message and any attachments. Thank you. </STRONG></P> --=_alternative 0045D15285257458_=-- --===============1308112039== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============1308112039==--