Here's a tip about a little-known but handy auditing tool demonstrated at the recent MCP TechMentor Conference, in San Diego by consultant and speaker Brian Komar.

EventCombMT is a Microsoft auditing tool that allows

    Requires Free Membership to View

you to search and pull Event Logs from multiple servers and across multiple domains.

This is not a new tool, so I was surprised at how many attendees didn't raise their hands when Komar asked who had heard of this tool or has used it. If you're leery about getting into the vast and dense world of logs, you should definitely know about this tool and take advantage of how simple it is to use.

EventCombMT allows an administrator to:

  • Search for a single Event ID, multiple Event IDs or even a range of Event IDs
  • Search for specific event types or sources
  • Search for specific text within an event

EventCombMT works for NT4, Windows 2000, XP and .NET. It allows you to search for any logs you wish: system, DNS, security, Active Directory -- you name it. The built-in searches make using it a breeze. Simply check off which log files you want to search and where you want to search -- i.e. all DCs in a domain, a single server, all GCs in a domain, etc. You can specify certain time frames for your searches as well.

This utility collects Event Logs in a text file in comma-delimited format, which allows you to easily import your logs into any database for analysis and historical archiving. Just make sure that you save your log files in a secure folder. There's no point in collecting security logs if you're just going to stick them on a shared drive where any wandering Joe can find them!

One thing to note is that you need to click and highlight whatever you add to your search window before running the search or it won't work. Intuitively you would think that because you've clicked "add" to insert an item into the search box that it would automatically be run against when you initiate the search. But this isn't the case. Hopefully, this heads up will save you some time trying to figure out why your searches are returning bogus results.

Your can download EventCombMT for free as part of Microsoft's Security Operations Guide for Windows 2000 Server. Before getting started with this tool, make sure you check out the EventCombMT information and screen shots in chapter six of the security guide.

This was first published in September 2002

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.