Event Log and Event ID Research
eventlogs.com

Research
The Event Log Defined
The Syslog Defined
The Event Log and
Today's Enterprise

Event IDs

Strategies
Event Log Management
and the Secure Network

Monitoring Event Logs
Auditing Event Logs
Event Correlation

Solutions
Monitoring Log Files
Collecting Log Files
Auditing Log Files
A Concept for
Total Log Management

Tools
Auditing Volume Analyzer


The Event Log Defined
On a Windows NT / 2000 / XP / 2003 network, an event is an action, and a grouping or listing of such actions is an event log (sometimes called event log file or just log file).

The action itself can be as simple as a successful (or failed) print job by someone at their machine in an office or a successful (or failed) log on by a computer user. For example, you generate an event whenever you log on to your computer at work.

The Microsoft Windows platform generates log files in several categories: Application, System, Security, DNS Server, Directory Service, and File Replication Service. Additionally, logs are generated by Microsoft Internet Information Services (also called Microsoft IIS).

As you can imagine, on any network, these logs grow quickly. Consider all the events you yourself or your computer running quietly by itself generate in a day. Now, imagine a network several times the size of the one that perhaps you use at your office.

Behind the scenes every day, computer networks across the globe are generating records of the events that occur. Some are routine. Others are indicators of a decline in network health or attempted security breaches.


Other resources:

Event Log Overview
Provided by Microsoft.

eventlogs.blogspot.com
See things through the eyes of the development department in a leading SEM / SIEM software firm and keep up on the complexities of the Windows Event Log and eventing.

HOW TO: Enable IIS Logging Site Activity in Windows 2000
Provided by Microsoft.