Month: May 2017
-

Monitoring your fleets event logs – Part 2
Install Splunk – It’s free! https://www.splunk.com/en_us/download/splunk-enterprise.html Modify Program Files\Splunk\etc\system\local\inputs.conf Add the lines [WinEventLog] evt_resolve_ad_obj = 1 Then we need to reboot splunk, in Splunk click Settings, then Server controls and click Restart Splunk Next we need to add our data source, click Add Data from the launch screen, then monitor Choose Local Events then ForwardedEvents and…
-

Monitoring your fleets event logs – Part 1
Windows has an amazing feature that let’s you collect logs from remote computers, it’s called Windows Event forwarding and is pretty easy to set up. Once we have this data we can use free tools such as Splunk or GrayLog to analyse the data, find patterns, fix. Below is the way to get started collecting…
Search
Recent Posts
Categories
- How-To (10)
- Posts (47)
- Uncategorized (51)
Tags
2019 acrobat adobe automation banner boot capture center citrix client configmgr deployment fix group policy how-to IIS inventory logfiles logs managementpoint memcm netapp nvivo office onedrive orchestrator osd oxygen packaging patch portal powershell pxe sccm slow soe software updates support sysctr terrible package troubleshooting tuesday Windows 10 windows file explorer advertising winpe