2011-11-09
05:29 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Undefined MSSQL messages messages on 2008 servers
We're running enVision 4.0 SP4 Patch 3. For Windows collection, we are on content 2.0. The most recent Windows ESU we have installed is from April 2011.
We collect MSSQL server logs from both Windows 2003 and Windows 2008 servers. The MSSQL logs collected from the Windows 2008 servers are all undefined and don't parse.
The message header is %NICWIN-4-Application_18453_MSSQLSERVER
I mean, like, half of the messages coming from these servers are Windows Application logs, but they're undefined. For one server, in the last hour it generated 130,000 messages, and 65,000 of them are undefined, and have the header above in them.
- Does anyone know if by now, November 2011, these Windows 2008 MSSQL server messages are defined and parse?
1 Reply
2011-11-10
08:12 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
MSSQL events parse against the MSSQL device type. If you are collecting windows security events as well as MSSQL application events from the same server then the IP of the server must be configured as a Multi-device. Based on your comments it looks like you only have a Windows (NIC) device discovered. Next step would be to manually add a MSSQL device type for that same IP and mark both of them as multi-device. The messages will then be parsed by their respective device types.
