We have relaunched: What's new at ZDNet Asia?

Using the Event Viewer snap-in

Summary

Get tips on using the Event Viewer, which displays items logged by the system when actions happen within a Windows Server 2003 system.

Events

The 2nd InfoSecurity Summit HK 2010
17 Mar 2010

Hong Kong Convention and Exhibition Centre, Hong Kong

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

Windows Server 2003 admins can benefit from using the various snap-ins included with the Computer Management Console. This tip offers a more detailed introduction to one of these snap-ins: Event Viewer. (To access the Computer Management Console in Windows Server 2003, right-click the My Computer Icon on the Start menu and select Manage with the left button.)

Event Viewer displays items logged by the system when actions happen within a Windows Server 2003 system. You can access the tool from the Run dialog by entering eventvwr and clicking OK.

By default, the events logged are captured in one of these log files:

  • System: Shows Windows system events.
  • Application: Shows events recorded by applications that are installed on the system.
  • Security: Contains records of logon/logoff actions and privilege use.

(Other applications--which include later versions of Microsoft Office and Internet Explorer, Microsoft Active Directory, and File Replication Services--may create their own logs, which will appear in the event log.)

Each of the logs included in Event Viewer by default allow you to quickly view actions taking place on a system. For example, the starting and stopping of services are recorded as informational entries in the System log.

The System and Application logs also record warning events and critical events. Warning events display events that are not immediate problems but could cause more serious issues if left unchecked. Critical events occur when a component or application fires an error when performing a task. An example of a critical event within the Directory Services log might be an error that occurs when the Domain Controllers in your Active Directory environment cannot replicate directory service information between each other. While this error can be caused by several things, including network outages or problems with DNS, it is classified as critical because it becomes a significant point of possible failure in your environment.

Backing up, clearing, and altering the size of event logs
You can also use Event Viewer to back up and clear the event logs. You may want to do this if a given log has reached its maximum size limit.

To clear a log of all the events it currently holds, follow these steps:

  1. In the left pane of the Computer Management Console, right-click the event log you want to clear and select Clear Log.
  2. Windows Server 2003 will ask you if you want to save the contents of the file before clearing it. Click Yes and then choose a location to save the contents of the log.
  3. Click Save. This will back up the contents of that log and clear it.

Follow these steps to change the size of a log:

  1. Right-click the log file object for which you wish to adjust the size and select Properties.
  2. Enter the new file size in the Maximum Size box (the default is 512 KB), then click OK.

Maintaining log files automatically
When the log files are created, they are assigned a default size of 512 KB. This size is usually easy to manage; however, if the system is accessed frequently and processes many logons, the Security log may become full more often than you like. If this happens, the PC will prevent logons by anyone who is not a member of the administrators group. (This is typically not an issue on a server system, but I’m using it as an example of an event that can occur that will fill the log file.)

To remedy full log files, you can assign one of the following actions to each log file:

  • Overwrite events as needed (overwrite the oldest events first)
  • Overwrite events older than xx days
  • Do not overwrite events (clear logs manually)

If you assign either of the first two options, it will allow the logs to manage themselves in terms of disk space.

Note: It's important to review log files on a regular basis to ensure that your Windows Server 2003 systems are functioning properly. The log archiving option will allow you to review the log files, while keeping the active logs manageable with little intervention.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

http://bit.ly/XHqoL Font Tools - Graphic Design Software - Windows - Free Software ... http://bit.ly/a9wykq

2 hours 57 minutes ago by rbwflyers on topsy

New Pfaffli Update! IT security insiders rob casinos of $50K http://ow.ly/16Phi6

4 hours 8 minutes ago by pfaffli on topsy

Holiday homes for sale : Community Blogs : ZDNet Asia http://bit.ly/9WVT4M

4 hours 40 minutes ago by moonflowerstarf on topsy

Slightly perturbed that ZDNet Asia now has a Cameron Daigle Tracker. http://bit.ly/9Wns4i

4 hours 46 minutes ago by camerondaigle on topsy

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Graphic Design Software - Windows - Free Software Downloads ... http://bit.ly/axan7d: Graphic Design... http://bit.ly/aTN5WG #graphicdesign

8 hours 17 minutes ago by graphicdesign24 on topsy

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Singapore govt (LTA) wants to provide live parking data to third parties. http://bit.ly/90Fc0m

RT @jay_ro: Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

ZDNet Australia, Asia and UK re-launch on a unified platform - looking good. www.zdnet.com.au www.zdnetasia.com www.zdnet.co.uk

Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

RT @pastawoua: The new ZDNet is live, www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) yay for unified design

RT @zdnetasia: We've cut over to a new design. Check out www.zdnetasia.com!

RT @pastawoua: new ZDNet is live zdnet.com.au (also zdnetasia.com & zdnet.co.uk) yay for unified design / Congratulations, it's a milestone

The new ZDNet is live, www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) yay for unified design

RT @zdnetasia: We've cut over to a new design. Check out www.zdnetasia.com!

RT @EileenZDNetAsia: We have finally crossed over...to the new ZDNet Asia look. Check it out! http://www.zdnetasia.com/

@ZDNetAsia's old look http://twitpic.com/193mvi in case you miss it.

We've cut over to a new design. Check out www.zdnetasia.com!

We have finally crossed over...to the new ZDNet Asia look. Check it out! http://www.zdnetasia.com/

Very good explanation of JMX

14 hours 41 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

17 hours 45 minutes ago by lonemavericks on diggs

Another ZTE story....

19 hours 47 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

22 hours 20 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

1 day 51 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

1 day 28 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

1 day 29 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

1 day 3 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

1 day 3 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

1 day 40 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

1 day 46 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

2 days 45 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

3 days 47 minutes ago by Anonymous on Hot tech jobs in Singapore

Good article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...

3 days 53 minutes ago by JN on What will social analytics say about your company?

The worlds most popular browser Firefox which has remained a stable trustworthy and secure product for many years now was today broken by...

4 days 3 minutes ago by Mitchell Krog on Mozilla aggressively asks older Firefox users to update

Nice article.. :) IOPS is a metric that has two more brothers. Throughput. and Latency. In effect, you must be aware of your IOPS,...

4 days 36 minutes ago by Karl Arao on Calculate IOPS in a storage array