Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

Wednesday, November 21, 2007

Interesting Post: Tracking Install/Uninstall Thru Logs

A quote: "In these days of malware, spyware, and compliance regulations, a lot of admins are looking to track the installation of unauthorized programs, and/or the removal of required programs from client desktops. There are actually several events you can look for in both the Application Event Log and Security Event Log that will help you do this." The Windows events involved are

Read on.

Wednesday, October 17, 2007

On Interpreting Windows Events - Comprehensive

This piece from Eric "Event Logger" Fitzgerald has pointers to more lists of Windows event information than you ever, ever, ever, ever :-) wanted to look at.

Examples are:
Eric also reveals the horrible uber-reason why some of Windows events have no documentation (oh, horror!): "... we count the number of hits for each OS Version/Source/Event ID combination and then our writing teams pester the component owners to populate that content."

Wednesday, August 08, 2007

More On LASSO and Windows Logging

Here is a small blurb that I did for CNET on LASSO (our open-source agentless Windows-to-syslog collector) and Windows log collection. BTW, a new version of LASSO is out.

One thing to keep in mind is that you don't need LogLogic appliances to use LASSO: it can forward events to syslog-ng or other syslog destinations. However, if you do need more than a syslog server, LASSO works perfectly with the appliances as well.

Tuesday, July 03, 2007

Dr Anton Chuvakin