In the first installment of this article, we reviewed some of the basics regarding Windows NT event logging, including the architecture of the Event Log service and ways to export Event Log information. In the second installment, I will demonstrate how to manage the function of logging Windows NT to syslog and look at an alternative to the vanilla syslog daemon. We will take a look at how to examine your syslog output to provide real-time analysis and alerting of system events. Finally, I will show you how to log your own events and what security-related events you should look for.
Read Entire Paper
E-Mail Link
Your IP address will be sent with this e-mail