Importing Windows Event Logs for Forensics
Updated: 21 May 2010 | 3 comments
I'm trying to take some windows event log files (evt) offsite to correlate with a SSIM appliance. Is this possible? Problem I'm running into is that when you open a windows event log file in event viewer the logs are only there temporarily. If you close event viewer the logs are not there the next time you log in. Thus, the sensor isn't picking up the names of the event viewer named files. Any easier way to do this?
discussion Filed Under:
Comments
Thanks Mate!!!
Would you like to reply?
Login or Register to post your comment.