<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Security Log Haystack – Event Forwarding and You</title><link>http://blogs.technet.com/b/askds/archive/2011/08/29/the-security-log-haystack-event-forwarding-and-you.aspx</link><description>Hi. This is your guest writer Mark Renoden . I&amp;rsquo;m a Senior Premier Field Engineer based in Sydney, Australia and I&amp;rsquo;m going to talk to you about the use of Event Forwarding to collect security events. This is particularly useful when: 
 
</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: The Security Log Haystack – Event Forwarding and You</title><link>http://blogs.technet.com/b/askds/archive/2011/08/29/the-security-log-haystack-event-forwarding-and-you.aspx#3449760</link><pubDate>Mon, 29 Aug 2011 16:16:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3449760</guid><dc:creator>sgrinker</dc:creator><description>&lt;p&gt;Awesome post... Event Forwarding is your friend!&lt;/p&gt;
&lt;p&gt;For anyone interested, you can couple Event Forwarding with PowerShell to essentially get a &amp;quot;poor mans&amp;quot; auditing utility. &amp;nbsp;Basically forwarding then parsing data from Security log audit events into SQL for alerting and reporting.&lt;/p&gt;
&lt;p&gt;Definitely not looking to self promote, but thought I&amp;#39;d share if anyone can find it useful. &amp;nbsp;I know it has definitely come in very handy around here, so hopefully someone else can find some use of the work.&lt;/p&gt;
&lt;p&gt;Please don&amp;#39;t use the comments here for any troubleshooting or assistance if you decide to use the module. &amp;nbsp;Anything additional regarding the utility should be posted at the CodePlex link...&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://pseventlogwatcher.codeplex.com/documentation"&gt;pseventlogwatcher.codeplex.com/documentation&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3449760" width="1" height="1"&gt;</description></item><item><title>re: The Security Log Haystack – Event Forwarding and You</title><link>http://blogs.technet.com/b/askds/archive/2011/08/29/the-security-log-haystack-event-forwarding-and-you.aspx#3449754</link><pubDate>Mon, 29 Aug 2011 15:56:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3449754</guid><dc:creator>aemiller</dc:creator><description>&lt;p&gt;I had done this about a year ago with my 2003 DCs. It was a pain. I am very happy to see this published and all in one place.&lt;/p&gt;
&lt;p&gt;Allan &amp;quot;You better get busy then&amp;quot; Miller&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3449754" width="1" height="1"&gt;</description></item></channel></rss>