Event Log Management

Event Log Monitoring, Analysis, Reporting and Archiving Software

Monitoring and reporting network-wide Windows servers, systems and network devices; along with compliance challenges and performance accuracy is a heavy responsibility. Your requirement under such a pressurized scenario would be a proactive event log monitoring solution that is potential and apt for the fast paced IT world, offering hi-tech, technically sound Windows log management solution. Plus, a tool that is compatible with all the versions of event logs: 

  • Windows 2003 server event logs
  • Windows 2008 activity logs
  • Windows NT logs
  • Windows 2000 events 
  • Windows XP performance logs
  • Windows Vista event logs
  • Windows 7 event logs

In this cloud computing age, cyber crime technology has advanced too, and this high scale of IT security breaches and cyber crimes require an even highly advanced Windows log monitoring solution that offers a hold on the security issues. What you seek in your Windows log monitoring solution is:

  • Deriving A-Z information related to Windows events
  • Continuously monitoring Windows activities
  • Automatically organizing event log data
  • Assistance in reinforcing security policies
  • Increasing IT efficiency while reducing downtime
  • Satisfying compliance audit requirements

EventLog Analyzer offers event log monitoring solutions that assist in secured business continuity even in the constantly evolving IT arena. If deployed, EventLog Analyzer performs to offer the following benefits:

  • Legal compliance and company policy adherence by retaining all the event log information required for audits
  • Compilation of several event logs centrally located for convenience and security backup purposes 
  • Stay on guard even in your absence! With the dynamic alerting feature that is configured and can be customized to alarm you on any suspicious, malicious activity occurrence
  • Automated archiving of Windows events and display of those Windows events that are of priority for the security admin personnel's view
  • Analyzing the Windows events logs for correct categorization of events to be systematically organized for better view and report generation
  • Narrow down your search by customizing the tool to view event logs that are specific to your relevance
  • Continuous monitoring without any manual intervention and attention requirement
  • High Scalability to incorporate large volumes of Windows events 

The solution is designed to perform a set of functions. The role of EventLog Analyzer event log monitoring system is as follows:

The ManageEngine Suite invites you for a free trial of EventLog Analyzer to try and test the product's worth. You are soon to explore the features and acknowledge the reasons for EventLog Analyzer to be a beneficial event log monitoring solution.

Some of the many Windows Event IDs and Windows Vista Event IDs recognized by EventLog Analyzer are listed below:

Windows Event ID Windows Vista Event ID Event Type Description
512, 513, 514, 515, 516, 518, 519, 520
4608, 4609, 4610, 4611, 4612, 4614, 4615, 4616
System Events
Identifies local system processes such as system startup and shutdown and changes to the system time
517
4612
Audit Logs Cleared
Identifies all the audit logs clearing events
528, 540
4624
Successful User Logons
Identifies all the user logon events
529, 530, 531, 532, 533, 534, 535, 536, 537, 539
4625
Logon Failures
Identifies all the failed user logon events
538
4634
Successful User Logoff
Identifies all the user logoff events
560, 563,  565, 566
4656, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 5147
Object Access
Identifies when a given object (File, Directory, etc.) is accessed, the type of access (e.g. read, write, delete) and whether or not access was successful/failed, and who performed the action
612
4719
Audit Policy Changes
Identifies all the changes done in the audit policy
624, 625, 626, 627, 628, 629, 630, 642, 644
4720, 4722, 4723, 4724, 4725, 4726, 4738, 4740
User Account Changes
Identifies all the changes done on an user account like user account creation,deletion, password change, etc.
(631 to 641) and (643, 645 to 666)
4727 to 4737, 4739 to 4762
User Group Changes
Identifies all the changes done on an user group such as adding or removing a global or local group, adding or removing members from a global or local group, etc.
672, 680
4768, 4776
Successful User Account Validation
Identifies successful user account logon events, which are generated when a domain user account is authenticated on a domain controller
675, 681
4771, 4777
Failed User Account Validation
Identifies unsuccessful user account logon events, which are generated when a domain user account is authenticated on a domain controller
682, 683
4778, 4779
Host Session Status
Identifies the session re-connection or disconnection

EventLog Analyzer also supports logs received from other syslog supported systems & devices.

Using EventLog Analyzer you can archive or store these event logs, and also generate event log reports in real-time. You get instant access to wide variety of reports for events generated across hosts, users, processes, and host groups. You can also obtain pre-defined compliance reports to meet HIPAA, GLBA, PCI, and Sarbanes-Oxley audit requirements.

Other features

Syslog management

Collect and analyze Syslog data from routers, switches, firewalls, IDS/IPS, Linux/Unix servers, and more. Get in-depth reports for every security event. Receive real-time alerts for anomalies and breaches.

Application log analysis

Analyze application log from IIS and Apache web servers, Oracle & MS SQL databases, DHCP Windows and Linux applications and more. Mitigate application security attacks with reports & real-time alerts.

Active Directory log monitoring

Monitor all types of log data from Active Directory infrastructure. Track failure incidents in real-time and build custom reports to monitor specific Active Directory events of your interest.

IIS log monitoring

Centrally monitor & audit IIS web server logs. Secure IIS servers by detecting anomalous events with instant email/SMS alerts. Get predefined reports on server errors and attacks.

Privileged user monitoring

Monitor and track privileged user activities to meet PUMA requirements. Get out-of-the-box reports on critical activities such as logon failures, reason for logon failure, and more.

IT compliance management

Comply with the stringent requirements of regulatory mandates viz., PCI DSS, FISMA, HIPAA, and more with predefined reports & alerts. Customize existing reports or build new reports to meet internal security needs.

Need Features? Tell Us
If you want to see additional features implemented in EventLog Analyzer, we would love to hear. Click here to continue

Customer Speaks
  • Credit Union of Denver has been using EventLog Analyzer for more than four years for our internal user activity monitoring. EventLog Analyzer provides great value as a network forensic tool and for regulatory due diligence. This product can rapidly be scaled to meet our dynamic business needs.
     
    Benjamin Shumaker
    Vice President of IT / ISO
    Credit Union of Denver
  • The best thing, I like about the application, is the well structured GUI and the automated reports. This is a great help for network engineers to monitor all the devices in a single dashboard. The canned reports are a clever piece of work.
     
    Joseph Graziano, MCSE CCA VCP
    Senior Network Engineer
    Citadel
  • EventLog Analyzer has been a good event log reporting and alerting solution for our information technology needs. It minimizes the amount of time we spent on filtering through event logs and provides almost near real-time notification of administratively defined alerts.
     
    Joseph E. Veretto
    Operations Review Specialist
    Office of Information System
    Florida Department of Transportation
  • I love the alerts feature of the product. We are able to send immediate alerts based on pretty much anything we can think of. We send alerts when certain accounts login, or when groups are changed, etc. That has been very helpful. Also the automatic archive of the log files has been very helpful and has taken the worry out of keeping old logs. The “Ask Me” function is very nice as well. It is great to have some natural language queries built in where you can just click a button and get an answer.
     
    Jim Earnshaw
    Senior Computer Specialist
    Department of Chemistry
    University of Washington
  • Windows Event logs and device Syslogs are a real time synopsis of what is happening on a computer or network. EventLog Analyzer is an economical, functional and easy-to-utilize tool that allows me to know what is going on in the network by pushing alerts and reports, both in real time and scheduled. It is a premium software Intrusion Detection System application.
     
    Jim Lloyd
    Information Systems Manager
    First Mountain Bank

EventLog Analyzer Trusted By

A Single Pane of Glass for Comprehensive Threat Management