RE: Windows Log Analysis
"Clayton Dukes (cdukes)" <[email protected]> Wed, 21 Oct 2009 12:03:36 -0400
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <579B1692B003C34EBE0C3BE1DF92F30701ED02F6@xmb-rtp-21e.amer.cisco.com> |
This is a multi-part message in MIME format. --===============2016053586== Content-class: urn:content-classes:message Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01CA5268.0D6E64FC" This is a multi-part message in MIME format. ------_=_NextPart_001_01CA5268.0D6E64FC Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable Hi Chris, I own an open source tool that a lot of people use for log analysis. I built the tool primarily for Cisco-based events, but there are a lot of people using it for Security and Windows-based log analysis. The project is located at http://code.google.com/p/php-syslog-ng if you are interested. I would also be interested in knowing if it is successfully being used for log analysis of non-Cisco environments, so if you use it, please let me know J =20 =20 =20 From: [email protected] [mailto:[email protected]] On Behalf Of chris misztur Sent: Thursday, October 08, 2009 9:41 AM To: [email protected] Subject: [logs] Windows Log Analysis =20 I've put this project off to the side since mid-2008 but I'm back at it (http://sync-io.net/go/blog/2008/06/18/EventCollectorSubscribingHTTPXP20 03ClientsPost1.aspx). I've been thinking up ways to utilize Windows Event Collector (http://msdn.microsoft.com/en-us/library/bb427443(VS.85).aspx <http://msdn.microsoft.com/en-us/library/bb427443%28VS.85%29.aspx> ) to collect from all PCs in the domain. The collector allows me to create subscriptions using xpath queries and have the logs forwarded from clients to the collector. I have been playing with the idea of polling all PCs in the domain, getting their available logs, sources and events (resource files in XP and above, and instrumentationManifests in Vista and above). From this data I should have visibility of *most* possible events in my domain. Great... so now I have a list of thousands possible events that I could collect. =20 Now what? How do I create a semi-autonomous system that will know to take action? (e.g. kerberos/5 and W32Time/29 should check the state of timeservers) I am tired of playing the game of collect everything and ask questions later. With a db of *most* Windows events, I should be able to make more intelligent decisions. chris =20 ------_=_NextPart_001_01CA5268.0D6E64FC Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:x=3D"urn:schemas-microsoft-com:office:excel" = xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint" = xmlns:a=3D"urn:schemas-microsoft-com:office:access" = xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" = xmlns:s=3D"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" = xmlns:rs=3D"urn:schemas-microsoft-com:rowset" xmlns:z=3D"#RowsetSchema" = xmlns:b=3D"urn:schemas-microsoft-com:office:publisher" = xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadsheet" = xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" = xmlns:odc=3D"urn:schemas-microsoft-com:office:odc" = xmlns:oa=3D"urn:schemas-microsoft-com:office:activation" = xmlns:html=3D"http://www.w3.org/TR/REC-html40" = xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/" = xmlns:rtc=3D"http://microsoft.com/officenet/conferencing" = xmlns:D=3D"DAV:" xmlns:Repl=3D"http://schemas.microsoft.com/repl/" = xmlns:mt=3D"http://schemas.microsoft.com/sharepoint/soap/meetings/" = xmlns:x2=3D"http://schemas.microsoft.com/office/excel/2003/xml" = xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd" = xmlns:ois=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" = xmlns:dir=3D"http://schemas.microsoft.com/sharepoint/soap/directory/" = xmlns:ds=3D"http://www.w3.org/2000/09/xmldsig#" = xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint/dsp" = xmlns:udc=3D"http://schemas.microsoft.com/data/udc" = xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema" = xmlns:sub=3D"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/"= xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#" = xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" = xmlns:sps=3D"http://schemas.microsoft.com/sharepoint/soap/" = xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance" = xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/soap" = xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile" = xmlns:udcp2p=3D"http://schemas.microsoft.com/data/udc/parttopart" = xmlns:wf=3D"http://schemas.microsoft.com/sharepoint/soap/workflow/" = xmlns:dsss=3D"http://schemas.microsoft.com/office/2006/digsig-setup" = xmlns:dssi=3D"http://schemas.microsoft.com/office/2006/digsig" = xmlns:mdssi=3D"http://schemas.openxmlformats.org/package/2006/digital-sig= nature" = xmlns:mver=3D"http://schemas.openxmlformats.org/markup-compatibility/2006= " xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns:mrels=3D"http://schemas.openxmlformats.org/package/2006/relationshi= ps" xmlns:spwp=3D"http://microsoft.com/sharepoint/webpartpages" = xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/types"= = xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/messag= es" = xmlns:pptsl=3D"http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/= " = xmlns:spsl=3D"http://microsoft.com/webservices/SharePointPortalServer/Pub= lishedLinksService" xmlns:Z=3D"urn:schemas-microsoft-com:" = xmlns:st=3D"" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Dus-ascii"> <meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)"> <style> <!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri","sans-serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} span.EmailStyle17 {mso-style-type:personal-reply; font-family:"Calibri","sans-serif"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.Section1 {page:Section1;} --> </style> <!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3DEN-US link=3Dblue vlink=3Dpurple> <div class=3DSection1> <p class=3DMsoNormal><span style=3D'color:#1F497D'>Hi = Chris,<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'color:#1F497D'>I own an open source = tool that a lot of people use for log analysis. I built the tool primarily for = Cisco-based events, but there are a lot of people using it for Security and = Windows-based log analysis.<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'color:#1F497D'>The project is = located at <a href=3D"http://code.google.com/p/php-syslog-ng">http://code.google.com/p/= php-syslog-ng</a> if you are interested.<o:p></o:p></span></p> <p class=3DMsoNormal><span style=3D'color:#1F497D'>I would also be = interested in knowing if it is successfully being used for log analysis of non-Cisco environments, so if you use it, please let me know </span><span style=3D'font-family:Wingdings;color:#1F497D'>J</span><span = style=3D'color:#1F497D'><o:p></o:p></span></p> <p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p> <p class=3DMsoNormal><span = style=3D'color:#1F497D'><o:p> </o:p></span></p> <div> <div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt = 0in 0in 0in'> <p class=3DMsoNormal><b><span = style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>= </b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> = [email protected] [mailto:[email protected]] <b>On Behalf Of </b>chris = misztur<br> <b>Sent:</b> Thursday, October 08, 2009 9:41 AM<br> <b>To:</b> [email protected]<br> <b>Subject:</b> [logs] Windows Log Analysis<o:p></o:p></span></p> </div> </div> <p class=3DMsoNormal><o:p> </o:p></p> <div> <div> <p class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"; color:black'>I've put this project off to the side since mid-2008 but = I'm back at it (<a href=3D"http://sync-io.net/go/blog/2008/06/18/EventCollectorSubscribingHT= TPXP2003ClientsPost1.aspx" target=3D"_blank">http://sync-io.net/go/blog/2008/06/18/EventCollectorSub= scribingHTTPXP2003ClientsPost1.aspx</a>). I've been thinking up ways to utilize Windows Event Collector (<a href=3D"http://msdn.microsoft.com/en-us/library/bb427443%28VS.85%29.aspx"= target=3D"_blank">http://msdn.microsoft.com/en-us/library/bb427443(VS.85)= .aspx</a>) to collect from all PCs in the domain. The collector allows me to = create subscriptions using xpath queries and have the logs forwarded from = clients to the collector. I have been playing with the idea of polling all = PCs in the domain, getting their available logs, sources and events = </span><span style=3D'color:black'>(resource files in XP and above, and instrumentationManifests in Vista and above). From this data I should = have visibility of *most* possible events in my domain. Great... so now = I have a list of thousands possible events that I could collect. <br> <br> Now what? How do I create a semi-autonomous system that will know = to take action? (e.g. kerberos/5 and W32Time/29 should check the state of = timeservers)<br> I am tired of playing the game of collect everything and ask questions = later. With a db of *most* Windows events, I should be able to make more = intelligent decisions.<br> <br> chris</span><span = style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"; color:black'><o:p></o:p></span></p> </div> </div> <p class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times = New Roman","serif"'><o:p> </o:p></span></p> </div> </body> </html> ------_=_NextPart_001_01CA5268.0D6E64FC-- --===============2016053586== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============2016053586==--