Page 1 of 1 1
Topic Options
#53216 - 2001-01-16 08:46 PM Information Eventlog Windows NT 4
Anonymous
Unregistered


Is it possible to use kixtart to look within
the eventlog files from Windows NT.
If not can someone tell me then which program I should use. And yes I know where to find the eventviewer which is delivered with Windows. I need the login and logout time of all users.

Thanx

Top
#53217 - 2001-01-16 09:06 PM Re: Information Eventlog Windows NT 4
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
Ace:

A quick search of the reskit uncovered this...

quote:

dumpel.exe

This command-line utility can be used to dump an event log into a tab-separated text file. It can also be used to apply a filter to find or exclude certain event types. You can use this utility to dump the event log of both local and remote systems.

To dump the system event log on server \\Eventsvr to a file Event.out:

dumpel -s eventsvr -l system -f event.out

To dump the local system event log, including only rdr events 2013:

dumpel -l system -m rdr -e 2013

To dump the local application log, and include all events except ones from the garbase source:

dumpel -l application -m garbase -r


Luck

Shawn.

[This message has been edited by Shawn (edited 16 January 2001).]

Top
#53218 - 2001-01-16 09:17 PM Re: Information Eventlog Windows NT 4
Anonymous
Unregistered


Thanx Shawn.
Can you mail me the program please.


Top
#53219 - 2001-01-16 09:47 PM Re: Information Eventlog Windows NT 4
Bryce Offline
KiX Supporter
*****

Registered: 2000-02-29
Posts: 3167
Loc: Houston TX
Ace,

dumpel.exe is a tool that comes with the NT Resource kit.

Now this raises a question that I don't know the answer to.

I got my copy of the Resource kit through my subscription to "MS Technet Plus". Is this the only way to get a copy of the resource kit? Or can you DL the resource kit from some hidden corner, behind the 3rd link on the left, on page number 2, knock twice, and the password of the day is "bubba", on the MS site?

Bryce

Top
#53220 - 2001-01-16 09:54 PM Re: Information Eventlog Windows NT 4
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
Bryce:

Funny you should mention that - I was just chatting with our on-site MS consultant (yup - we have one - full time) and I posed this question to him (because I'm brain-washed) and this is what he said...

The NT4 reskit was not free because it came with the MSDN subscription (don't know if that's true or not).

The Win2K reskit is totally free.

Does that make sense to anyone ?

Does this mean that the NT4 reskit is now free ?

Anyone ?

Shawn.

Top
#53221 - 2001-01-16 09:59 PM Re: Information Eventlog Windows NT 4
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
hmmm...


Free Windows 2000 Resource Kit Tools for Administrative Tasks

Shawn.

Top
#53222 - 2001-01-16 10:39 PM Re: Information Eventlog Windows NT 4
kholm Offline
Korg Regular
*****

Registered: 2000-06-19
Posts: 714
Loc: Randers, Denmark
Shawn

Ask your consultant again!

I found this text at the end of the download pages for the free tools:

Buy the Resource Kits

Windows 2000 Server Resource Kit
Windows 2000 Professional Resource Kit

So still not free?

Erik

ps. When you buy software today it only seems that you get the basics. If you want it to do what you expected it to when you bought it, you have to buy something more.
I have two more examples in our backup software and firewall software

[This message has been edited by kholm (edited 16 January 2001).]

Top
#53223 - 2001-01-16 10:49 PM Re: Information Eventlog Windows NT 4
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
My consultant just ran over to my desk and told me that the NT reskit is now free...

Doing a search, I found that a "subset" of the kit is now free...

Windows NT 4.0 Resource Kit Support Tools

[I haven't downloaded this yet - don't know what's in it]

Shawn.


Top
#53224 - 2001-01-17 02:16 PM Re: Information Eventlog Windows NT 4
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
Ace:

Well - if you haven't already download it ( I just did) - dumpel.exe is included in the free Windows NT Resource Kix Support Tools ...

Kix on - my brother !

Shawn.

Top
#53225 - 2001-01-17 02:26 PM Re: Information Eventlog Windows NT 4
Wizard Offline
Hey THIS is FUN
*****

Registered: 2000-12-05
Posts: 264
Loc: Bristol, England
The 'Free' part of the ResKit is like a demo of some software.

You get a small about of the full thing, a subset as Spawn put it.

Then, when/if you buy the full product, you get a nice shiney CD with it all on


On the other hand, if you have access to the Microsoft Select Option, you can get hold of the full thing for free - apparently.!

Mike

_________________________
Wizard
There's no place like 127.0.0.1

vb | kix | batch | html | cfm | js | english

Top
#53226 - 2001-01-17 02:53 PM Re: Information Eventlog Windows NT 4
Anonymous
Unregistered


The Windows NT Resource Kit is a book. The latest version (supplement 4) could be reviewed at http://www.amazon.com/exec/obidos/ASIN/0735608377

As far as I know, it was originally ONLY a book. Then something appeared on MS Web, and now many of its utilities are freely downloadable. KIXTART itself was always included with it. It's also included in the MS Technet subscription.


Returning to the question, do not forget the BACKUPEVENTLOG() function of Kixtart (since the 3.61 version). The file obtained could be easily scanned with readline to look for specific data. But, from my point of view :
1. it's easier (and quicker) to place some code in the login script of the users.
2. do not rely too much on logout events on the Event Viewer. Users like a lot to switch off the power instead then logging out ...

Top
Page 1 of 1 1


Moderator:  Glenn Barnas, NTDOC, Arend_, Jochen, Radimus, Allen, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 460 anonymous users online.
Newest Members
Sir_Barrington, batdk82, StuTheCoder, M_Moore, BeeEm
17886 Registered Users

Generated in 0.058 seconds in which 0.025 seconds were spent on a total of 12 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org