Hands-On Microsoft Windows Server 2008



Similar documents
Understand Troubleshooting Methodology

June 20, Copyright 2012 by World Class CAD, LLC. All Rights Reserved.

Server Manager Performance Monitor. Server Manager Diagnostics Page. . Information. . Audit Success. . Audit Failure

Also on the Performance tab, you will find a button labeled Resource Monitor. You can invoke Resource Monitor for additional analysis of the system.

EVENT VIEWER IN WINDOWS 7

Lab 14A: Using Task Manager and Event Viewer

Integrating LANGuardian with Active Directory

FIGURE Selecting properties for the event log.

WINDOWS PROCESSES AND SERVICES

11.1. Performance Monitoring

TROUBLESHOOTING INCORRECT REPORTING OF THE WHO CHANGED PARAMETER

Advanced Event Viewer Manual

Events Forensic Tools for Microsoft Windows

Net Report Configuration Guide for WMI on Windows 2000 & XP

Installing Active Directory

Hands-On Microsoft Windows Server 2008

Safewhere*ADFS2Logging

NETWRIX WINDOWS SERVER CHANGE REPORTER

RSA Security Analytics

Using. - Training Documentation -

Installation Steps for PAN User-ID Agent

CONFIGURING TARGET ACTIVE DIRECTORY DOMAIN FOR AUDIT BY NETWRIX AUDITOR

Dell Active Administrator 8.0

Find the Who, What, Where and When of Your Active Directory

Monitoring Windows Event Logs

Dell Active Administrator 8.0. About Active Administrator 8.0

How to Manage a Windows NT Server Computer Remotely

Log Management and Intrusion Detection

Setting up Sharp MX-Color Imagers for Inbound Fax Routing to or Network Folder

PRODUCT WHITE PAPER LABEL ARCHIVE. Adding and Configuring Active Directory Users in LABEL ARCHIVE

Table of Contents WELCOME TO ADAUDIT PLUS Release Notes... 4 Contact ZOHO Corp... 5 ADAUDIT PLUS TERMINOLOGIES... 7 GETTING STARTED...

ACTIVE DIRECTORY DEPLOYMENT

QUANTIFY INSTALLATION GUIDE

The Institute of Internal Auditors Detroit Chapter Presents

Chapter 8 Monitoring and Logging

Server Manager Help 10/6/2014 1

Introduction. Before you begin. Installing efax from our CD-ROM. Installing efax after downloading from the internet

RSA Authentication Manager 8.1 Virtual Appliance Getting Started

NETWRIX FILE SERVER CHANGE REPORTER

NAS 206 Using NAS with Windows Active Directory

IDENTIKEY Appliance Administrator Guide

RSA Event Source Configuration Guide. Microsoft Exchange Server

TECHNICAL REFERENCE GUIDE

Microsoft Office 365 Using SAML Integration Guide

DC Agent Troubleshooting

Centran Version 4 Getting Started Guide KABA MAS. Table Of Contents

Virtual Office Remote Installation Guide

Network Event Viewer now supports real-time monitoring enabling system administrators to be notified immediately when critical events are logged.

Installation Guide for Pulse on Windows Server 2008R2

Citrix Access Gateway Plug-in for Windows User Guide

Deploying Remote Desktop Connection Broker with High Availability Step-by-Step Guide

Sage 200 Web Time & Expenses Guide

Pcounter Web Report 3.x Installation Guide - v Pcounter Web Report Installation Guide Version 3.4

Trial environment setup. Exchange Server Archiver - 3.0

Introduction. Activating the CFR Module License. CFR Configuration

CompleteView Admin Console Users Guide. Version Revised: 02/15/2008

Getting Started Guide

Acronis Backup & Recovery 11.5 Quick Start Guide

HOW TO CONNECT TO FTP.TARGETANALYSIS.COM USING FILEZILLA. Installation

WhatsUp Event Analyst v10.x Quick Setup Guide

Acronis Backup & Recovery 11

Active Directory Integration for Greentree

Implementing and Supporting Microsoft Windows XP Professional

HP StorageWorks Library and Tape Tools FAQ

Using Group Policies to Install AutoCAD. CMMU 5405 Nate Bartley 9/22/2005

Docufide Client Installation Guide for Windows

Sage HRMS 2014 Sage Employee Self Service Tech Installation Guide for Windows 2003, 2008, and October 2013

How to install Small Business Server 2003 in an existing Active

SpectorSoft Log Manager Help

Workshop 5051A: Monitoring and Troubleshooting Microsoft Exchange Server 2007

For details for obtaining this later version; see the Known issues & Limitations, section at the end of this document.

Lepide Event Log Manager. Users Help Manual. Lepide Event Log Manager. Lepide Software Private Limited. Page 1

Joining. Domain. Windows XP Pro

How To Configure CU*BASE Encryption

Viewing and Troubleshooting Perfmon Logs

Secrets of Event Viewer for Active Directory Security Auditing Lepide Software

This document details the following four steps in setting up a Web Server (aka Internet Information Services -IIS) on Windows XP:

Installation Guide for Pulse on Windows Server 2012

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

NETWRIX ACCOUNT LOCKOUT EXAMINER

How to Give Admin Rights to Students on the ADGRM Domain

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

WatchGuard Mobile User VPN Guide

User Replicator USER S GUIDE

Application Note 116: Gauntlet System High Availability Using Replication

PC Security and Maintenance

Using Process Monitor

IBM Security QRadar SIEM Version MR1. Administration Guide

How to Connect to Berkeley College Virtual Lab Using Windows

Getting Started With Delegated Administration

Converting InfoPlus.21 Data to a Microsoft SQL Server 2000 Database

ManageEngine Exchange Reporter Plus :: Help Documentation WELCOME TO EXCHANGE REPORTER PLUS... 4 GETTING STARTED... 7 DASHBOARD VIEW...

Endpoint Security Console. Version 3.0 User Guide

CTI Installation Manual Version 1.0

AdminToys Suite. Installation & Setup Guide

Installation Notes for Outpost Network Security (ONS) version 3.2

Only for Data Group Students Do not share with outsiders and do not use for commercial purposes.

Dwebs IIS Log Archiver Installation and Configuration Guide for Helm 4

Configuring VPN Using Windows XP

Transcription:

Hands-On Microsoft Windows Server 2008 Chapter 10 Managing System Reliability and Availability Using and Configuring Event Viewer Event Viewer Houses the event logs that record information about all types of server events, in the form of errors, warnings, and informational events Windows Server 2008 event logs are divided into three general categories: 1. Windows logs 2. Applications and services logs 3. Microsoft logs Hands-On Microsoft Windows Server 2008 2 1

Hands-On Microsoft Windows Server 2008 3 Using and Configuring Event Viewer (continued) 1. Windows Logs: generates four logs for reporting general operating system and software application events: System log Hardware errors, driver problems, and hard drive errors. Security log Access and security information about logon accesses, and system policy changes. Application log Records information about how software applications are performing Setup log Contains a record of installation events, such as installing a role or feature through Server Manager. Hands-On Microsoft Windows Server 2008 4 2

Using and Configuring Event Viewer (continued) 2. Applications And Services Logs: Combined of Operational and Admin log as follows: Operational log Tracks occurrences of specific operations. Example: such as when a disk drive is added Admin logs Help to give the system administrator information about a specific problem and its causes and may suggest how to solve the problem Example: Reporting that the DFS Replication service has failed and that this might be caused by the Windows Firewall configuration. Hands-On Microsoft Windows Server 2008 5 Using and Configuring Event Viewer (continued) Applications and services logs available in Event Viewer include: DFS Replication log Records events for the Distributed File System Replication services Directory Service log Records events that are associated with Active Directory DNS Server log Records events that are associated with Domain Name System services Hardware Events Records events related to hardware including the CPU, disk drives, memory, and other hardware Internet Explorer Records events related to Internet Explorer Hands-On Microsoft Windows Server 2008 6 3

Using and Configuring Event Viewer (continued) For more complex detailed application and services logs: Analytic logs Relate to how programs are operating and are typically used by application or system programmers Debug logs Used by application developers to help trace problems in programs so they can fix program code or program structures Hands-On Microsoft Windows Server 2008 7 Viewing Log Events Log events are displayed in Event Viewer with an icon that indicates the seriousness of the event Each log displays descriptive information about individual events, including the following: Description of the event Name of the log in which the event is recorded Source of the event Event ID Level of the event information, warning, error User associated with the event, if any Hands-On Microsoft Windows Server 2008 8 4

Viewing Log Events (continued) Hands-On Microsoft Windows Server 2008 9 Viewing Log Events (continued) Event Viewer can be opened from: Administrative Tools menu Computer Management tool Server Manager To view the contents of a log, click that log in the tree under Event Viewer To view the detailed information about an event, double-click the event The event logs are a good source of information to help you troubleshoot a software or hardware problem Hands-On Microsoft Windows Server 2008 10 5

Viewing The Content a Log In the following example we double clicked on the Application log that is included inside Windows Logs Hands-On Microsoft Windows Server 2008 11 Using the Event Viewer Filter Option All of the event logs in Event Viewer have a filter option to help you quickly locate a problem The events can be filtered on the basis of the following criteria: When the event was Logged, such as in the last seven days Event level, such as information, warning, error, critical, and verbose By log, such as the application, system or security log By source of the event, such as a particular service or software component Hands-On Microsoft Windows Server 2008 12 6

Using the Event Viewer Filter Option (continued) The events can be filtered on the basis of the following criteria: (continued) Task category of the event, such as a security change Keywords, such as Audit Failure and Audit Success User associated with the event Computer associated with the event Date range Time of day range Hands-On Microsoft Windows Server 2008 13 Example: Using the Filter Option with the Application log Hands-On Microsoft Windows Server 2008 14 7

Maintaining Event Logs Event logs can be quickly filled with information Logs can be maintained using several methods, as follows: Size each log to prevent it from filling too quickly Overwrite the oldest events when the log is full Archive the log when it is full Clear the log manually (does not overwrite events) It is recommended that you develop a maintenance schedule To save the log contents for a designated time period Hands-On Microsoft Windows Server 2008 15 Maintaining Event Logs (continued) To tune the event logs, open Event Viewer and right-click each log you want to tune, one at a time And click Properties On the General tab, set the log size in the Maximum log size (KB): box You can save the log as one of the following kinds of files: Microsoft Event Viewer logs (.evtx) EXtensible Markup Language (.xml) Text File (.txt) Comma Delimited File (.csv) can be opened from Microsoft Excel. Hands-On Microsoft Windows Server 2008 16 8

Maintaining Event Logs Hands-On Microsoft Windows Server 2008 17 9