Security Compliance

Logging events under Application and Services Logs

This article provides information if you would like to log events from any log in the Application and Services Logs tree in Event Viewer.

First published date

10/11/2018 3:43 PM

Last published date

10/11/2018 3:43 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

This article provides information if you would like to log events from any log in the Windows Application and Services Logs tree in Event Viewer.

Product section

Security Event Manager

Resolution

Each individual log file in that tree technically requires its own connector in order for SEM to parse its events. Several of these logs are currently supported and you will find a connector with the same name as the log itself in your node's connectors list.

For any log that isn't currently listed, we can create a new connector if you are able to raise a case with SolarWinds Support and provide the following items:

  • Log name (this includes the name of the log, Windows application by Microsoft/vendor definition, version of the Microsoft/vendor application, and the Windows operating system version)
  • Path to the log in Event Viewer (this is the navigation path used by Event Viewer)
  • Log path to the file the events are stored in (found by right-clicking the log, going to Properties, and looking at the Log path field). Screenshots are also helpful.
  • A sample log file. (this would be a copy of the actual log file, exported/saved from Event Viewer with the "English" language option, which produces the needed meta-data of the event definitions.)
    You can send us the EVTX log (& meta-data file) located at the Log path you found above or export specific events in Event Viewer by filtering and clicking Save All Events As under the Actions pane, but be sure we have all applicable events for creating a connector that will parse all applicable events.
  • If there are any specific events desired, or additional information that you can provide, please include that.
    It helps reduce possible re-work, and improve the chances to create the connector on the first try.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.