Comments (4)
Perhaps I misunderstand what you are trying to filter. Are you wanting to just
filter on those IDs, or do you want to also filter on some criteria within
those IDs?
Original comment by [email protected]
on 20 May 2011 at 2:38
from eventlog-to-syslog.
On some criteria actually.
Say, I have a server that does Antivirus and produces ~6 million service logins
(with users like WS0000$) over the day.
My only option with evtsys is to
* send them, which does generate heaploads of traffic
* Squeeze them into the DB, since I wouldn't want to apply a general filter
that early
* Remove them with a simple cron later on(DELETE FROM SYSTEMEVENTS WHERE
EVENTUSER LIKE '%$' AND EVENTID IN (<list of eventids id like to remvoe from>);
Instead I'd rather apply a regex filter on the client side and save a heapload
of traffic, central logging host operations, mysql time and crons :)
Original comment by [email protected]
on 20 May 2011 at 9:25
from eventlog-to-syslog.
And just to add, I need to send them because they frankly use the same EventIDs
as other logons(4624 and 4634) :/
Original comment by [email protected]
on 20 May 2011 at 9:26
from eventlog-to-syslog.
I know this was posted quite some time ago, but thought I would update it. This
won't be possible in any short period of time because adding filtering or regex
capability would require some extended research and testing. If someone would
like to put in the effort and submit a patch I would be happy to include it.
-Sherwin
Original comment by [email protected]
on 8 Jul 2011 at 3:43
- Changed state: WontFix
- Added labels: Type-Enhancement
- Removed labels: Type-Defect
from eventlog-to-syslog.
Related Issues (20)
- Google Code closing
- How to capture system reboot log?
- Evtsys doesn't start automatically on Windows
- How can I get User field transferred to syslog
- Wrong "File version" number at EXE-file HOT 2
- could be installed on hyper-v server (core) HOT 3
- Host configuration don't work at instalation HOT 2
- -a option only working in console mode HOT 2
- Events not showing HOT 3
- Specify Security, Application, or System event? HOT 2
- evtsys service (via svchost process) burn all CPU HOT 5
- service not work anymore from suspend state HOT 3
- Evtsys consumes almost all memory of the server HOT 5
- version 4.5.1 does not start service on Windows Server 2008 R2 HOT 1
- Is it possible to failover between servers, instead of sending to all servers?
- Cannot initialize access to registry: "System\CurrentControlSet\Services\EventLog\Application\EvtSys"
- Unable to load multiple EventSource:EventIDs in config file HOT 1
- Does not work on Server 2012 HOT 1
- evtsys.cfg do not seem to work
- Windows Server 2003 config file problem
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from eventlog-to-syslog.