Write event log entries from host to domain controller

From: corn29_at_ no_spam excite.com (corn29_at_excite.com)
Date: 05/17/04


Date: 16 May 2004 23:44:03 -0700

Hi,

Is there anyway to write the events written to a local computer's
event log to another machine (like a domain controller)? Preferably a
native way and NOT requiring some third party app.

I tried on one of my hosts to change the File key at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\
from %SystemRoot%\system32\config\SecEvent.Evt to
\\DC1\%SystemRoot%\system32\config\SysEvent.Evt and all it did was
copy security events to the application log on the same host... no
entries from the host's log were written to the DC's security log!

I'm hoping that there's a vbscript way to do this and I can make it a
service. I could always have this security event log forwarder
service running and it would make administration of the security log
(forwarding security log entires from all acorss the domain to a
single machine) a lot easier.

I'm pretty desperate... if anyone can help me out, I'd name my
first-born after them! ;)

Thanks!



Relevant Pages

  • RE: Event ID 643
    ... After researching the event log, I have found the Caller User Name is ... CSMONITOR$ in the security log, it seems the system has raised this error. ... Event log 1704 has indicated that security policy in the Group policy ...
    (microsoft.public.win2000.security)
  • Re: Subject: Security Event Log reading by Domain Users
    ... our "program" is a SQL script run trough Microsoft Log Parser. ... > account will also be able to clear the security log. ... Event Log under Domain User account? ...
    (microsoft.public.win2000.security)
  • Re: Subject: Security Event Log reading by Domain Users
    ... account will also be able to clear the security log. ... Event Log under Domain User account? ... > Adding a "Manage auditing and sec. log" and "Act as the part of oper. ... > I added all possible rights to the Domain User account, from "Create a Token Object" to "Generate> Security audits", but no luck. ...
    (microsoft.public.win2000.security)
  • RE: Event ID 643
    ... I set up another machine in a lab the same way as our DATACENTERNYC machines ... with IIS and the local security policy. ... > Thanks for the event log! ... > CSMONITOR$ in the security log, it seems the system has raised this error. ...
    (microsoft.public.win2000.security)
  • Re: Active directory problem
    ... The root domain controller is taking much longer time to ... The event log on root domain controller is showing ... so there is no replication going on to ...
    (microsoft.public.win2000.active_directory)