Looking at windows logs

"James B Horwath" <[email protected]> Thu, 29 May 2008 08:42:36 -0400
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <OF2A512BCF.0530C525-ON85257458.0038B2FE-85257458.0045D153@glic.com>
This is a multi-part message in MIME format.


--===============1308112039==
Content-Transfer-Encoding: 7bit
Content-Class: urn:content-classes:message
Content-Type: multipart/alternative;
	boundary="=_alternative 0045D15285257458_="

This is a multi-part message in MIME format.


--=_alternative 0045D15285257458_=
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit

I hope somebody can help me.   I have a windows EVT file from a system 
that I want to view on another computer (which is a windows XP laptop). I 
booted the laptop with Linux (backtrack) and tried to remove the old 
security.evt file and replace it with mine.  Even with the windows drive 
mounted with "rw" I could manipulate any of the files or permissions.  I 
kept receiving a message "read-only" media.

I thought maybe I could use the eventquery.vbs file from the command line 
using the /L switch  to dump the logs, this did not work. It appears only 
the windows categories are readable.  I have a licensed copy of Adiscon 
eventviewer and a copy of lasso. 

Can anyone offer any suggestions on how to extract this data?

Thanks in advance.
Jim

 


-----------------------------------------
This message, and any attachments to it, may contain information
that is privileged, confidential, and exempt from disclosure under
applicable law.  If the reader of this message is not the intended
recipient, you are notified that any use, dissemination,
distribution, copying, or communication of this message is strictly
prohibited.  If you have received this message in error, please
notify the sender immediately by return e-mail and delete the
message and any attachments.  Thank you.
--=_alternative 0045D15285257458_=
Content-Type: text/html;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit


<br><font size=2 face="sans-serif"><br>
I hope somebody can help me. &nbsp; I have a windows EVT file from a system
that I want to view on another computer (which is a windows XP laptop).
&nbsp; I booted the laptop with Linux (backtrack) and tried to remove the
old security.evt file and replace it with mine. &nbsp;Even with the windows
drive mounted with &quot;rw&quot; I could manipulate any of the files or
permissions. &nbsp;I kept receiving a message &quot;read-only&quot; media.</font>
<br>
<br><font size=2 face="sans-serif">I thought maybe I could use the eventquery.vbs
file from the command line using the /L switch &nbsp;to dump the logs,
this did not work. It appears only the windows categories are readable.
&nbsp;I have a licensed copy of Adiscon eventviewer and a copy of lasso.
&nbsp;</font>
<br>
<br><font size=2 face="sans-serif">Can anyone offer any suggestions on
how to extract this data?</font>
<br>
<br><font size=2 face="sans-serif">Thanks in advance.</font>
<br><font size=2 face="sans-serif">Jim</font>
<br>
<br><font size=2 face="sans-serif">&nbsp;</font>
<P><hr size=1></P>
<P><STRONG>
This message, and any attachments to it, may contain information that is privileged, confidential, and exempt from disclosure under applicable law.  If the reader of this message is not the intended recipient, you are notified that any use, dissemination, distribution, copying, or communication of this message is strictly prohibited.  If you have received this message in error, please notify the sender immediately by return e-mail and delete the message and any attachments.  Thank you.
</STRONG></P>
--=_alternative 0045D15285257458_=--

--===============1308112039==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
LogAnalysis mailing list
[email protected]
http://www.loganalysis.org/mailman/listinfo/loganalysis
--===============1308112039==--