Closed GoogleCodeExporter closed 8 years ago
That is the correct configuration file. Can you explain to me exactly what the
problem is, or what you are trying to do? Are you currently running the utility?
When you run evtsys.exe and point it to a syslog server it should forward
everything that occurs in the event logs to the syslog server, including
Application, System, Security, etc.
Original comment by sherwin....@gmail.com
on 15 Apr 2011 at 2:52
Sorry it was error from Windows Server 2008 instead of eventlog. I was trying
to get events for account managements. I.e. get event logs for things like
creating, deleting and changing user accounts. The event log for account
managements wasn't configured. I believe this is a default configuration. If
anyone is having difficulties with this give me a shout and I will be happy to
help. I got this solved now and everything is working properly. Thank you for
getting back to me. This is a great tool, does exactly what I needed and in my
opinion Much! better than Snare.
Original comment by mustafea...@gmail.com
on 16 Apr 2011 at 6:42
I'm glad the utility is able to meet your needs. I will close this issue now.
-Sherwin
Original comment by sherwin....@gmail.com
on 17 Apr 2011 at 4:49
I installed the service using the following command:
evtsys.exe -i -h hostname.domain -l 0
But the server does not receive logs for Application !
I could not install more than one facility through the key "-f". So I left the
default value (3).
Which facility should be set to receive all logs?
Original comment by saturnsu...@gmail.com
on 7 Jul 2011 at 4:21
Original issue reported on code.google.com by
mustafea...@gmail.com
on 13 Apr 2011 at 4:32