RE: Looking at windows logs
"Pauls, Nicole" <[email protected]> Thu, 29 May 2008 11:49:34 -0700
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <A7CC499CF05307438D4B8EC3A159FA0C4186DCF6@postoffice.corp.trigeo.com> |
--===============2142466482== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_A7CC499CF05307438D4B8EC3A159FA0C4186DCF6postofficecorpt_" --_000_A7CC499CF05307438D4B8EC3A159FA0C4186DCF6postofficecorpt_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable If you want to open an .evt for just plain viewing, you should be able to b= oot another Windows system, open Event Viewer, and right click -> "Open Log= File..." You need to know what type of log file it is (Application, System= , Security, etc) or Windows will complain. If you wanted to REPLACE the event log with your older event log for some r= eason (say, to extract the data to a log management tool that can only acce= ss your running Security/System/Application event logs), you should be able= to: 1. Change the current Event Log settings to match size of your new .e= vt file (in event viewer -> select log -> properties) 2. Mark the EventLog service as disabled and reboot 3. After reboot, replace the target .evt in C:\windows\system32\confi= g 4. Mark EventLog service as automatic and reboot After you reboot, you can just use the Event Viewer to view the file "as if= " it was your normal .evt. New events will also get appended to the replace= ment log, though, so if you have auditing enabled and it's a Security Log, = you will find the "old" data along with the "new" data. You would need to t= ell your log management tool to start from the head of the log in order to = pull the data in (rather than the tail, which would only be new data). HTH -- nicole pauls, cissp-issap,issmp director, product management www.trigeo.com<http://www.trigeo.com> From: [email protected] [mailto:loganalysis-bounces@logan= alysis.org] On Behalf Of James B Horwath Sent: Thursday, May 29, 2008 5:43 AM To: [email protected]; [email protected] Subject: [logs] Looking at windows logs I hope somebody can help me. I have a windows EVT file from a system that= I want to view on another computer (which is a windows XP laptop). I boo= ted the laptop with Linux (backtrack) and tried to remove the old security.= evt file and replace it with mine. Even with the windows drive mounted wit= h "rw" I could manipulate any of the files or permissions. I kept receivin= g a message "read-only" media. I thought maybe I could use the eventquery.vbs file from the command line u= sing the /L switch to dump the logs, this did not work. It appears only th= e windows categories are readable. I have a licensed copy of Adiscon event= viewer and a copy of lasso. Can anyone offer any suggestions on how to extract this data? Thanks in advance. Jim ________________________________ This message, and any attachments to it, may contain information that is pr= ivileged, confidential, and exempt from disclosure under applicable law. If= the reader of this message is not the intended recipient, you are notified= that any use, dissemination, distribution, copying, or communication of th= is message is strictly prohibited. If you have received this message in err= or, please notify the sender immediately by return e-mail and delete the me= ssage and any attachments. Thank you. --_000_A7CC499CF05307438D4B8EC3A159FA0C4186DCF6postofficecorpt_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:x=3D"urn:schemas-microsoft-com:office:excel" xmlns:p=3D"urn:schemas-m= icrosoft-com:office:powerpoint" xmlns:a=3D"urn:schemas-microsoft-com:office= :access" xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s=3D"= uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs=3D"urn:schemas-microsof= t-com:rowset" xmlns:z=3D"#RowsetSchema" xmlns:b=3D"urn:schemas-microsoft-co= m:office:publisher" xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadshee= t" xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" xmlns= :oa=3D"urn:schemas-microsoft-com:office:activation" xmlns:html=3D"http://ww= w.w3.org/TR/REC-html40" xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope= /" xmlns:D=3D"DAV:" xmlns:x2=3D"http://schemas.microsoft.com/office/excel/2= 003/xml" xmlns:ois=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" xm= lns:dir=3D"http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:d= s=3D"http://www.w3.org/2000/09/xmldsig#" xmlns:dsp=3D"http://schemas.micros= oft.com/sharepoint/dsp" xmlns:udc=3D"http://schemas.microsoft.com/data/udc"= xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema" xmlns:sub=3D"http://schemas= .microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec=3D"http://www.w3.or= g/2001/04/xmlenc#" xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" xm= lns:sps=3D"http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi=3D"http= ://www.w3.org/2001/XMLSchema-instance" xmlns:udcxf=3D"http://schemas.micros= oft.com/data/udc/xmlfile" xmlns:wf=3D"http://schemas.microsoft.com/sharepoi= nt/soap/workflow/" xmlns:mver=3D"http://schemas.openxmlformats.org/markup-c= ompatibility/2006" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/o= mml" xmlns:mrels=3D"http://schemas.openxmlformats.org/package/2006/relation= ships" xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/t= ypes" xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/me= ssages" xmlns:Z=3D"urn:schemas-microsoft-com:" xmlns=3D"http://www.w3.org/T= R/REC-html40"> <head> <meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii"> <meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)"> <!--[if !mso]> <style> v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style> <![endif]--> <style> <!-- /* Font Definitions */ @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} p {mso-style-priority:99; mso-margin-top-alt:auto; margin-right:0in; mso-margin-bottom-alt:auto; margin-left:0in; font-size:12.0pt; font-family:"Times New Roman","serif";} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {mso-style-priority:34; margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif";} span.EmailStyle19 {mso-style-type:personal-reply; font-family:"Calibri","sans-serif"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.Section1 {page:Section1;} /* List Definitions */ @list l0 {mso-list-id:1667005562; mso-list-type:hybrid; mso-list-template-ids:-434189272 67698703 67698713 67698715 67698703 67698= 713 67698715 67698703 67698713 67698715;} @list l0:level1 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --> </style> <!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3DEN-US link=3Dblue vlink=3Dpurple> <div class=3DSection1> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>If you want to open an .evt for just plain viewing, you shou= ld be able to boot another Windows system, open Event Viewer, and right click -> “Open Log File…” You need to know what type of log = file it is (Application, System, Security, etc) or Windows will complain. <o:p><= /o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>If you wanted to REPLACE the event log with your older event= log for some reason (say, to extract the data to a log management tool that can only access your running Security/System/Application event logs), you shoul= d be able to:<o:p></o:p></span></p> <p class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'= ><span style=3D'mso-list:Ignore'>1.<span style=3D'font:7.0pt "Times New Roman"'>&n= bsp; </span></span></span><![endif]><span style=3D'font-size:11.0pt;font-family:= "Calibri","sans-serif"; color:#1F497D'>Change the current Event Log settings to match size of your = new .evt file (in event viewer -> select log -> properties)<o:p></o:p></span><= /p> <p class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'= ><span style=3D'mso-list:Ignore'>2.<span style=3D'font:7.0pt "Times New Roman"'>&n= bsp; </span></span></span><![endif]><span style=3D'font-size:11.0pt;font-family:= "Calibri","sans-serif"; color:#1F497D'>Mark the EventLog service as disabled and reboot<o:p></o:p><= /span></p> <p class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'= ><span style=3D'mso-list:Ignore'>3.<span style=3D'font:7.0pt "Times New Roman"'>&n= bsp; </span></span></span><![endif]><span style=3D'font-size:11.0pt;font-family:= "Calibri","sans-serif"; color:#1F497D'>After reboot, replace the target .evt in C:\windows\system32\config<o:p></o:p></span></p> <p class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'= ><span style=3D'mso-list:Ignore'>4.<span style=3D'font:7.0pt "Times New Roman"'>&n= bsp; </span></span></span><![endif]><span style=3D'font-size:11.0pt;font-family:= "Calibri","sans-serif"; color:#1F497D'>Mark EventLog service as automatic and reboot<o:p></o:p></sp= an></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>After you reboot, you can just use the Event Viewer to view = the file “as if” it was your normal .evt. New events will also get appended to the replacement log, though, so if you have auditing enabled an= d it’s a Security Log, you will find the “old” data along with the = 220;new” data. You would need to tell your log management tool to start from the hea= d of the log in order to pull the data in (rather than the tail, which would onl= y be new data).<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>HTH<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>-- <o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>nicole pauls, cissp-issap,issmp<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'>director, product management<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><a href=3D"http://www.trigeo.com">www.trigeo.com</a> <o:p></= o:p></span></p> <p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri",= "sans-serif"; color:#1F497D'><o:p> </o:p></span></p> <div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in = 4.0pt'> <div> <div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in = 0in 0in'> <p class=3DMsoNormal><b><span style=3D'font-size:10.0pt;font-family:"Tahoma= ","sans-serif"'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> [email protected] [mailto:[email protected]] <b>On Behalf Of </b>James B Horwath<br> <b>Sent:</b> Thursday, May 29, 2008 5:43 AM<br> <b>To:</b> [email protected]; [email protected]= <br> <b>Subject:</b> [logs] Looking at windows logs<o:p></o:p></span></p> </div> </div> <p class=3DMsoNormal><o:p> </o:p></p> <p class=3DMsoNormal><br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'><br> I hope somebody can help me. I have a windows EVT file from a system that I want to view on another computer (which is a windows XP laptop). &nb= sp; I booted the laptop with Linux (backtrack) and tried to remove the old security.evt file and replace it with mine. Even with the windows dri= ve mounted with "rw" I could manipulate any of the files or permissi= ons. I kept receiving a message "read-only" media.</span> <br> <br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>I thought= maybe I could use the eventquery.vbs file from the command line using the /L swit= ch to dump the logs, this did not work. It appears only the windows categories are readable. I have a licensed copy of Adiscon eventviewe= r and a copy of lasso. </span> <br> <br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>Can anyon= e offer any suggestions on how to extract this data?</span> <br> <br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>Thanks in advance.</span> <br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>Jim</span= > <br> <br> <span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'> </s= pan> <o:p></o:p></p> <div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'> <hr size=3D1 width=3D"100%" align=3Dcenter> </div> <p><strong>This message, and any attachments to it, may contain information that is privileged, confidential, and exempt from disclosure under applicab= le law. If the reader of this message is not the intended recipient, you are notified that any use, dissemination, distribution, copying, or communicati= on of this message is strictly prohibited. If you have received this message i= n error, please notify the sender immediately by return e-mail and delete the message and any attachments. Thank you. </strong><o:p></o:p></p> </div> </div> </body> </html> --_000_A7CC499CF05307438D4B8EC3A159FA0C4186DCF6postofficecorpt_-- --===============2142466482== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============2142466482==--