Welcome to TechNet Blogs Sign in | Join | Help

Syndication

Tags

    No tags have been created or used yet.
User Requests

The following is one of the user requests that was received.

 

1) being able to forward a log item to a DB, possibly in asyc mode (e.g. MSMQ, BITS) and/or to MOM/SMS for analysis and proactive maintainance (e.g. push out a FIX with SMS)

2) group events into 1 items instead of having hundreds of same items

3) please do the logs in a XML (parsable) format

4) ability to redirect/map logs to a network share

5) Larger default sizes

6) Automatic rollover (daily/weekly/x items)logs - old logs to be stored on disk

 

 

Here is the reply

 

1) It will be possible to subscribe to a log using a filter.  The subscriber could then forward the events. 

2) Right now there is no plan to support Event aggregation as part of service natively but this can easily be done by enterprise products which are written on top of this infrastructure.

3) The new system is based on xml.  The internal format isn’t xml text, but getting an xml representation of the log will be quite easy through rendering.  A utility will ship that will take an xpath expression and create an xml text file

4) The issue with that is that the service will not generally have access to network share.  It will be possible to create or read backup on the network, but not to have live logs there since that requires the service to have access without an active client. Two things which might help here. The firt one is that new Eventlog does provide the way to change the local location for the log. Secondly, one can use Event forwarding to forward it to other machines.

5) Done

6) We do have the capability to create a backup and clear the log once it hits a certain size.  We don’t base the backup on time in eventlog service. Alternatively, one can schedule a task (based on new Task Scheduler) to run a commandline at a certain time.

Published Monday, September 12, 2005 8:56 PM by Tejinder

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

# re: User Requests @ Sunday, December 21, 2008 1:42 PM

Great post, explained really well and I could really understand. Thank you.

pc forum

# re: User Requests @ Saturday, December 27, 2008 3:03 PM

okay, i understand that event logs need to be cleared. my problem is that one, since the logs were cleared, my computer no longer allows me to logon!!! what then? i have been locked out of my own computer and there's nobody else but me who owns this computer AND this operating system...this whole smear about SECURITY is a crock!!! especially, since i am a home PC user, i am not a part of a "network" and i don't want to "logon" as an administrator or anything else. i just want to user my @%!*@#$ COMPUTER!!!!!! WHAT in the hell is going on that i can't even use my computer!!!!! i get error messages like, "your account has expired, please see your system administrator" I AM MY OWN SYSTEM ADMINISTRATOR!!!! and for the life of me i tried everything to get passed that "NTLM AUTHENTICATION" BULLsh--- but i couldn't. so i reformatted another partition on my hard disk.  NOW i just got an error message, "audit failure fatal error", so i read my events log and it said something to the effect that not all of the network interfaces were available or whatever, but the error log continued with, "this could be a potential security leak, therefore user rights will be removed....and blah, blah, blah!!! so i went to administrative tools to make the necessary adjustments, you know, "turning on" the services because when i try to save the "console.mmc" i get the error message that "this console cannot be saved".  just now i went to wmi control properties to set the security at the root\cimv2 level and i was "denied access to any Win32 processes" NOW WHAT?!!!!  i am just about at the end of my rope and SERIOUSLY considering TRASHING windows altogether.  there are other os's like eclipse and solaris and others...go ahead and ask me if i have tried EVERYTHING!!! go ahead. because i have run ANTI-VIRUS programs to see if this could be a virus and every one of them come up empty!!! like norton 360, norton a/v 2005 & 2007, norton internet security suite, CA anti-virus, Avira a/v, Panda a/v, mcfee, rootkit anti-virus, not to mention ANTI-SPYWARE ANTI-ADWARE....got any suggestions? because as soon as turn my computer off--which i refuse to--i won't be able to get back on...thanks anyway...MaryAnn R. Vasquez aka submarelime@hotmail.com or submarelime@yahoo.com @#$#@#$%#@!!#$x;'

submarelime

# re: User Requests @ Saturday, December 27, 2008 3:03 PM

okay, i understand that event logs need to be cleared. my problem is that one, since the logs were cleared, my computer no longer allows me to logon!!! what then? i have been locked out of my own computer and there's nobody else but me who owns this computer AND this operating system...this whole smear about SECURITY is a crock!!! especially, since i am a home PC user, i am not a part of a "network" and i don't want to "logon" as an administrator or anything else. i just want to user my @%!*@#$ COMPUTER!!!!!! WHAT in the hell is going on that i can't even use my computer!!!!! i get error messages like, "your account has expired, please see your system administrator" I AM MY OWN SYSTEM ADMINISTRATOR!!!! and for the life of me i tried everything to get passed that "NTLM AUTHENTICATION" BULLsh--- but i couldn't. so i reformatted another partition on my hard disk.  NOW i just got an error message, "audit failure fatal error", so i read my events log and it said something to the effect that not all of the network interfaces were available or whatever, but the error log continued with, "this could be a potential security leak, therefore user rights will be removed....and blah, blah, blah!!! so i went to administrative tools to make the necessary adjustments, you know, "turning on" the services because when i try to save the "console.mmc" i get the error message that "this console cannot be saved".  just now i went to wmi control properties to set the security at the root\cimv2 level and i was "denied access to any Win32 processes" NOW WHAT?!!!!  i am just about at the end of my rope and SERIOUSLY considering TRASHING windows altogether.  there are other os's like eclipse and solaris and others...go ahead and ask me if i have tried EVERYTHING!!! go ahead. because i have run ANTI-VIRUS programs to see if this could be a virus and every one of them come up empty!!! like norton 360, norton a/v 2005 & 2007, norton internet security suite, CA anti-virus, Avira a/v, Panda a/v, mcfee, rootkit anti-virus, not to mention ANTI-SPYWARE ANTI-ADWARE....got any suggestions? because as soon as turn my computer off--which i refuse to--i won't be able to get back on...thanks anyway...MaryAnn R. Vasquez aka submarelime@hotmail.com or submarelime@yahoo.com @#$#@#$%#@!!#$x;'

submarelime

Leave a Comment

(required) 
required 
(required) 

  
Enter Code Here: Required
© 2009 Microsoft Corporation. All rights reserved. Terms of Use  |  Trademarks  |  Privacy Statement  
Page view tracker