Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 2003

OS Event-Log Monitoring

Automate event-log monitoring and catch potential problems before they occur
RSS
Subscribe to Windows IT Pro | See More Windows NT 4.0 Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

EDITOR'S NOTE: The Buyer's Guide summarizes vendor-submitted information. To find out about future Buyer's Guide topics or to learn how to include your product in an upcoming Buyer's Guide, go to http://www.winnetmag.com/buyersguide.

Consistently monitoring the Windows event logs should be an integral part of any network-management plan. In a perfect world, you'd review the logs every day and attend to significant events immediately. Unfortunately, network administrators are busy and often don't have time to check logs—a dilemma that can result in network crashes.

Shrinking budgets, staff cutbacks, and management requiring everyone to do more with less have forced drastic changes on the business environment. Network administrators need ways to work smarter. For example, if you had time to regularly review event logs, you could practice proactive network management. The tools in this issue's Buyer's Guide help you manage event logs so that you can work smarter.

When a given event occurs, most OS event-log monitoring tools notify you by pager, email, pop-up box, or through Microsoft Systems Management Server (SMS). Look for a solution that features flexible notification so that you can be notified by pager when crucial events occur and by email or another method when less crucial events occur. You probably don't need to know whether a print job was successful, but you must know as soon as possible if the Microsoft Exchange Server Store Service suddenly fails. Look for tools that let you define notifications by event type, category, and keyword.

Event trend analysis is a troubleshooting feature you should look for. When researching a particular event, you want to be able to easily discover whether the event occurred in the past. Although you can set filters in the Event Viewer to capture past events, often these events are overwritten and their history is lost. Look for a tool that automatically stores events so that you can analyze this data later. When you have trend-capturing capability, you can use a utility that determines the time interval between specific events as a troubleshooting tool. For example, when Active Directory (AD) events occur on a regular basis, you can analyze the time span between events to help troubleshoot AD or other synchronizing type of errors. Sometimes synchronization errors occur over a time span longer than 24 hours, thus the time interval between errors isn't obvious.

Another useful feature is the ability to annotate the event log. When you have this capability and similar events occur in the future, you won't have to reinvent the wheel. You can simply refer to your notes and quickly solve the recurring problem by using the solution you devised earlier.

The event-log monitoring tools in this guide are especially useful when you have many servers spread across a WAN. Then, you can receive fast notification about events and address them before a situation becomes a problem. Ideally, you shouldn't have to install the tools on each server, but this varies depending on the tool.

When you're ready to invest in an OS event-log monitoring tool, make sure you can access your servers remotely on a secure channel. That feature will let you solve many events remotely or at least temporarily fix the problem until you can get into the office. Installing Windows 2000 Server Terminal Services in Administrator Mode on Windows Server 2003 and Win2K is a powerful remote management solution.

All of the products in this Buyer's Guide let you monitor the Event Viewer by using the "management by exception" model, so you can set alerts for crucial events that have the potential to crash the server or cause network disruptions. Find a product that fits your company's requirements. Some tools specialize in monitoring events, while other tools offer a complete network-management package. Use these tools to work smarter instead of harder and to keep close tabs on the health of your network.

End of Article



Reader Comments
expecting a nice e book from you.

jayavardhan May 31, 2004


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Related Events WinConnections and Microsoft® Exchange Connections

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement