Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| slapdash:windows_logging [2017/04/26 13:08] – [Terminology] mgupton | slapdash:windows_logging [2023/03/21 16:41] (current) – mgupton | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ======Windows Logging (Slapdash)====== | ======Windows Logging (Slapdash)====== | ||
| - | ======wevtutil====== | + | <WRAP round info> |
| - | * // | + | This is a slapdash, slipshod, scattershot, |
| - | * [[http:// | + | </WRAP> |
| - | * [[http:// | + | |
| - | ====Terminology==== | + | ======Terminology====== |
| * Windows Event Log | * Windows Event Log | ||
| * channels | * channels | ||
| Line 11: | Line 10: | ||
| * providers | * providers | ||
| * streams | * streams | ||
| + | |||
| + | ======wevtutil====== | ||
| + | * // | ||
| + | * [[http:// | ||
| + | * [[http:// | ||
| + | |||
| + | ======Specific Events of Note====== | ||
| + | * [[Windows Administrator Activity Events]] | ||
| ======Listing Log Channels and Publishers====== | ======Listing Log Channels and Publishers====== | ||
| + | |||
| ====Enumerate a list of all log channels==== | ====Enumerate a list of all log channels==== | ||
| < | < | ||
| Line 403: | Line 411: | ||
| reg query hklm\system\currentcontrolset\services\eventlog | reg query hklm\system\currentcontrolset\services\eventlog | ||
| </ | </ | ||
| - | ======Resources====== | + | |
| - | * [[https:// | + | |
| ======To Explore====== | ======To Explore====== | ||
| Line 573: | Line 580: | ||
| logman query providers | logman query providers | ||
| </ | </ | ||
| + | |||
| + | ======Resources====== | ||
| + | * [[https:// | ||
| + | * webinars | ||
| + | * forum | ||
| + | * [[https:// | ||
| + | |||
| + | ====== Windows Object Auditing ====== | ||
| + | * #FIM | ||
| + | * [[https:// | ||
| + | |||