Solutions for the Maintenance of Event Logs
eventlogs.com

Research
The Event Log Defined
The Syslog Defined
The Event Log and
Today's Enterprise

Event IDs

Strategies
Event Log Management
and the Secure Network

Monitoring Event Logs
Auditing Event Logs
Event Correlation

Solutions
Monitoring Log Files
Collecting Log Files
Auditing Log Files
A Concept for
Total Log Management

Tools
Auditing Volume Analyzer

Collecting Log Files

As was suggested in the Strategies section of this site, automation, storage type, and compression are keys considerations in the selection of an event collection and storage solution.

When selecting an event collection, storage, and housing solution keep in mind that because automation is key in how effective the solution will be, this should not be a solution that you are spending time with daily or even weekly. Automation means that the solution is hands-off and that hopefully, you can configure it once and revisit it only when a tweak is absolutely necessary.

There are a number of other factors that ease the burden of implementing a solution, and as with any event software, see that your selection is agent-free if possible. Beyond ease of configuration, a number of features available will enhance your selection's return on investment:

  • Does it support FTP of log files?

  • What databases are supported?

  • Are proprietary database table structures required by the software or does it give you the flexibility you need to maintain the database?

  • What mechanisms are in place to ensure that no event data are lost?

  • Is compression supported natively?

  • Does it run as a service?


Other resources:

Event Archiver
Event Archiver is an automated log file collection and consolidation tool.