Jump to content

Windows Event Log Management

Microsoft Windows operating systems generate a variety of event log messages that aid in maintaining security operations, document application and system access, and more. If your environment includes Windows servers and workstations, it is critical that your log management solution support Windows events across its multiple versions in one solution.

Windows EVT Event Log Format

The Windows NT, XP, 2000 and 2003 server and workstation versions support the EVT log format. These logs can be viewed using the Windows Event Viewer across local or remote machines. However without intelligent filtering, multiple log viewing and comparison, and other capabilities, this process is cumbersome at best and unusable at its worst. Typical log sources include system, security and application log types. Each event type - for example, when a user authentication fails or system component fails to start - is recognized through its unique Event id.

Windows EVTX Event Log Format

With the launch of Windows Vista and Server 2008 versions, Microsoft changed their log management format to EVTX and the system is commonly called the Windows Event Log. While this new format supports a well defined structure and offers expanded fields to better enable applications to precisely log events and administrators to more easily interpret them – it breaks away from the earlier EVT format in a number of respects. EVTX has different event ID’s, a higher number of fields and supports different sources for logging of events data. Working with both EVT and EVTX formats in the same environment requires normalization to a common data structure. This need is met by WhatsUp Event Log Management’s patented and exclusive Log Refiner™ Technology. 

With WhatsUp Event Log Management solutions for Windows you can:

  • Monitor, collect, analyze, report and store Windows event log files across both the EVT and EVTX versions
  • Enable the identification and detection of network security events like repeated logon failures or unexpected change in role privileges for a group or an individual user
  • Make comprehensive Windows event log data and reports available for internal and regulatory compliance audit to internal management and auditors
  • Provide user friendly capabilities for routine event log review, analysis and scheduled reporting
  • Manage Windows event logs remotely from a central location or locally on a host machine as required
  • Assign segmented log administration and viewing rights to team members based on organizational needs and management structure