Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
slapdash:windows_logging [2017/04/26 12:54] – mgupton | slapdash:windows_logging [2023/03/21 16:41] (current) – mgupton | ||
---|---|---|---|
Line 1: | Line 1: | ||
======Windows Logging (Slapdash)====== | ======Windows Logging (Slapdash)====== | ||
- | ======wevtutil====== | + | <WRAP round info> |
- | * // | + | This is a slapdash, slipshod, scattershot, |
- | * [[http:// | + | </WRAP> |
- | * [[http:// | + | |
- | ====Terminology==== | + | ======Terminology====== |
+ | * Windows Event Log | ||
* channels | * channels | ||
* publishers | * publishers | ||
* providers | * providers | ||
* streams | * streams | ||
+ | |||
+ | ======wevtutil====== | ||
+ | * // | ||
+ | * [[http:// | ||
+ | * [[http:// | ||
+ | |||
+ | ======Specific Events of Note====== | ||
+ | * [[Windows Administrator Activity Events]] | ||
======Listing Log Channels and Publishers====== | ======Listing Log Channels and Publishers====== | ||
+ | |||
====Enumerate a list of all log channels==== | ====Enumerate a list of all log channels==== | ||
< | < | ||
Line 64: | Line 73: | ||
======Event Queries====== | ======Event Queries====== | ||
+ | * The following shows how to query Windows Event Log for events. | ||
* One way to get the XPath queries used by the /q option of // | * One way to get the XPath queries used by the /q option of // | ||
- | ===Query the last 5 logs from the //Security// log channel.=== | + | ===Query the last 5 logs from the Security log channel.=== |
+ | |||
+ | * Using %%/ | ||
- | Using %%/ | ||
< | < | ||
wevtutil qe Security /c:5 /rd:true /f:text | wevtutil qe Security /c:5 /rd:true /f:text | ||
Line 401: | Line 411: | ||
reg query hklm\system\currentcontrolset\services\eventlog | reg query hklm\system\currentcontrolset\services\eventlog | ||
</ | </ | ||
- | ======Resources====== | + | |
- | * [[https:// | + | |
======To Explore====== | ======To Explore====== | ||
Line 571: | Line 580: | ||
logman query providers | logman query providers | ||
</ | </ | ||
+ | |||
+ | ======Resources====== | ||
+ | * [[https:// | ||
+ | * webinars | ||
+ | * forum | ||
+ | * [[https:// | ||
+ | |||
+ | ====== Windows Object Auditing ====== | ||
+ | * #FIM | ||
+ | * [[https:// | ||
+ |