my boss wants to know how the windows 2008 eventlog (with new structure and look and feel) could be monitored with ipmonitor and what should be paid attention to?
Hello Schitti,
At this time the logs within the "Windows Logs" can be monitored in the same manner as monitoring event logs on any Windows machine.
The logs within the "Applications and Services branch" of the Event Logs cannot be monitored over WMI. More on this is found here:
http://social.technet.microsoft.com/Forums/en-US/windowsserver2008r2management/thread/ff3b5c60-0101-4fd4-968e-24f5bbd6de5c/
http://stackoverflow.com/questions/2382896/how-to-collect-the-new-applications-and-services-logs-found-on-windows-7-or-win
Having that said, as the ipMonitor Event Log Monitor uses WMI queries, it cannot monitor log events within this specific branch.
In order to get around this, you would need to write a Perl script and trigger it using the External Process Monitor.
Hope this helps.
Sincerely,
Chris Foley | Support RepSolarWinds | IT Management, Inspired By YouSupport:866.530.8040 || Fax:512.857.0125