2009-12-28
12:32 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Windows Event Logs - Import existing logs
We are thinking about adding a specific group of Windows workstations to be monitored in enVision. Is it possible to have all existing logs on the workstations added to enVision as well? I am familiar with using lsmaint -rebuild to add events already in enVision to a device that, for instance, was removed as a monitored device then added again. However, I am not familiar enough with the entire process that enVision follows to take the data from log format to the point it is added to the database. Is there a way to either make enVision grab the existing logs from the source? Or perhaps convert the current event logs on the Windows workstations to some other format and import them in a different manner?
1 Reply
2009-12-29
03:26 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I'm not aware of any easy way to extract the logs into the proper format for injection back into enVision.
Obviously if you are using an agent (Snare or EventReporter) then you can configure those agents accordingly. However I will point out that enVision treats these as seperate devices. So if you start with say Snare and then move to the agentless collector, you will see two devices listed for the same system.
I will raise this idea with development team that's working on the new Windows event collector service to see if they can make this a configurable option within the gui.
