Talk With an Expert

Centralizing Event Logs on Windows 2000

Centralizing Event Logs on Windows 2000 (PDF, 2.39MB)Published: 04 Apr, 2003
Created by:
Gregory Lalla

This case study will detail how I setup a central repository for server logs and daily notifications of events that might indicate a security incident. This was done on a limited budget using free tools available from the internet and software already in use for other projects. My goal was to consolidate the Eventviewer logs, Internet Information Services (IIS) logs, and Urlscan logs from 15 Windows 2000 web servers into a database I could query against. I would then have the results of the queries automatically emailed to me.