Re: please help to extract security event log

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Aug 3, 11:14 am, "gs" <g...@xxxxxxxxxxxxxx> wrote:
I am trying to track down some security issue and the exported log file is
too big to look with details and the filtered export got too little details

I want to select security events of " logon/logoff" category between say
2007-07-30 03:00 to 09:00
and get details like
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 2007-07-30
Time: 08:37:45
User: NT AUTHORITY\SYSTEM
Computer: SEDXXS01
Description:
Successful Network Logon:
User Name: SEDXXS01$
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {dd3d7aca-9890-1ea0-e89c-845a04976eac}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 195.228.223.101
Source Port: 3747

For more information, see Help and Support Center athttp://go.microsoft.com/fwlink/events.asp.

you might want to look at how to use the microsoft logparser
http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07

.



Relevant Pages

  • Re: Since W2003 SP1, many event 537 (failed logon)
    ... > Event Category: Logon/Logoff ... You will be taken to the proper newsgroup that will be able to help ... > Logon Failure: ... > Caller User Name: ...
    (microsoft.public.windowsupdate)
  • Re: Many Logon/Logoff Entries
    ... last week-end troubleshooting a Logon/LogOff issue and discovered just how ... over 170,000 of these entries in the Security Log. ... > Logon ID: ... > Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Security event crazyness... help!
    ... 540/538 as teh even type here is even log entries, ... Event Category: Logon/Logoff ... Successful Network Logon: ... Caller User Name: - ...
    (microsoft.public.windows.server.general)
  • too many logon/logoff events in security log
    ... I turn on the audit policy to monitor the logon/logoff envents in security ... However, there is too many logon/logoff events, average 3 times per ... Logon ID: ... Caller User Name: - ...
    (microsoft.public.windows.server.security)
  • Re: KDC Event ID 7 and Wins startup errors.
    ... Event Type: Information ... Event Source: USER32 ... Logon Failure: ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)