Skillfully use forwarding and subscriptions to centrally manage server logs

Source: Internet
Author: User
Tags exit log system log

Event Log management is a very important day-to-day work in server maintenance, and it is also an energy-intensive effort, especially when there are a lot of application servers in the LAN. A good management scenario is to deploy a central server dedicated to event log management, and then forward logs from other servers to the central server for centralized administration. However, this needs to be implemented using Third-party software. A new feature is provided in Windows Server 2008, which enables us to implement the forwarding and subscription of server event logs, and can customize the management of specific server event logs. The following author deploys the environment to illustrate this.

Environment Description:

This article takes the domain environment as an example to demonstrate that there are two servers: one for Server1, as the source server to forward logs to the log server, and one for the Server2, as a log server to subscribe to the logs forwarded at the source server.

Mission Objectives:

The error system log with ID 100 in the last 24 hours of the Server1 server is forwarded to the log server Server2 in real time, and once the Server1 has a log in place, the administrator is notified in the form of a message box on the Server2.

Implementation process:

1. Create a custom view

Log on to the Server1 server as an administrator, click start → run, and enter Eventvwr.msc to open the Event Viewer window. Click "Customize View" in the left pane and click to expand the Action menu to select the Create custom View command. In the Filter tab of the Create Custom View wizard window, set the record time to the past 24 hours, event level is error, and event log as System. " When you have finished setting, click OK to exit, and in the "Save filter to Custom View" dialog box that pops up, we name the view "Error Events" and then "hours" to exit. This allows you to see a view of the name "Error Events (Hours)" that you just created under Custom view. (Figure 1)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.