SlideShare a Scribd company logo
1 of 19
Consolidate all your Event Logs
                                                             in one Place!



CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                 1
Agenda

     » Are Event Logs Important
     » Event Log Management
     » SolarWinds Event Log Consolidator
              Using the Tool
     » Helpful Resources
       » SolarWinds Log & Event Manager




CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                2
Are Event Logs important?
»      Event logs on Windows systems are helpful for both troubleshooting
       when things go wrong and monitoring performance and behavior.


»      The First thing a System Administrator does to monitor any unusual
       activity is to check the system log files, it is the first and the most basic
       step in intrusion detection.


»      Every time there is a problem with a Windows server SysAdmins start by
       examining errors in the system and application event logs.


»      In an occurrence of an intrusion, security log entries can be isolated and
       preserved. These entries can be valuable during an investigation of the
       intrusion.



    CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                    3
Event Log Management
»      Logging on to each Windows System to see Event Logs is super tiring and
       cumbersome.


»      Need to view, consolidate, and dismiss event logs and correlate issues
       among multiple Windows systems quickly and easily from one central
       location?


»      Don’t have a centralized way to view all of your event logs?



          Here comes a SolarWinds
                Super Hero….


    CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                    4
SolarWinds Event Log Consolidator

                                       SolarWinds Event Log Consolidator can
                                       not only assist you in organizing all your
                                       event logs from Windows Systems in one
                                       location but also give you the ability view,
                                       and dismiss event logs and

»      Correlate issues among multiple Windows systems quickly and easily from one
       central location!
»      View, consolidate, and dismiss event logs from multiple Windows systems
»      Filter logs to see data that is important to you! Then, export key data to a .csv
       file
»      Enter your device information for up to 5 computers running Windows Server


    CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                    5
Adding a Windows Server
» To add a Windows server after launching the tool for the first time:
  Step 1: Enter the server name or IP address
  Step 2: Enter a username for a user with administrative privileges.
  Note: Enter DomainUsername for domain users.
  Step 3: Enter and confirm the password for the administrative user.
  Step 4: Click Test.
  Step 5: If you want to add another server, click Save & Add Another Server and
  repeat the steps above for up to 4 additional servers.
  Step 6: Click Save to view the Dashboard for your servers.


 The Dashboard consists of the following sections
 Total Number of Events: This section shows the number of events for each server in
 a bar chart. Point to a bar to see detailed information about that server.
 Event Details: This section shows the details of every event collected by the tool.
 Click an event to view its details in the lower pane of this section .

CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                6
Comparing Servers
» Comparing Servers Using the Side by Side View
   Click the Side by Side button on the Dashboard tab to view events from two of
   your monitored servers in a side-by-side view. This view aligns similar events so
   you can correlate these events across your selected servers.

   To use the Side by Side view
   Step 1: Open SolarWinds Event Log Consolidator.
   Step 2: Click the Dashboard tab.
   Step 3: Click Side by Side.
   Step 4: Modify the time range and choose a filter, and then click Refresh.
   Step 5: Select the servers you want to view.
   Step 6: Select or clear the boxes in the column headers to specify what types of
   values can constitute a correlation between your servers.
   Step 7: Click Refresh to load new data or apply any changes.
   Step 8: When you are finished, click Close.


CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                7
Adding/ Comparing Servers




               Credentials Entering Screen          Tool also gives you the ability to view Windows Event
                                                    logs both graphically over time as well as drill into
                                                    Specific Events to view the details

CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                8
Exporting Logs
» Exporting Consolidated Logs
   Click the Export button on the Dashboard tab to export the events that are currently displayed on that
   tab.
   To Export Consolidated Log Data
   Step 1: Open SolarWinds Event Log Consolidator.
   Step 2: Click the Dashboard tab.
   Step 3: Modify the time frame, selected servers, or filter to specify what you want to export.
   Step 4: Click Export.
   Step 5: Click Browse to browse to the folder in which you want to save the exported file and specify a
   filename.
          Note: If you do not specify a folder, the default save location is My Documents.
   Step 6: Select one of the following export options.
           Export All Columns: Exports all columns of the data defined by your current Dashboard view in CSV
           format.
           Select Columns to Export: Exports selected columns of the data defined by your current Dashboard
           view in CSV format. Clear a column's check box to omit it from the export.
           Export To Image: Exports the bar chart from your current Dashboard view in PNG format.
   Step 7: Click Export.



CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                        9
Adding / Editing Servers
Add and edit monitored servers on the Settings tab.
11    To Add a New Server                                     22 To Edit a Monitored Server
     Step 1: Open SolarWinds Event Log Consolidator.            Step 1: Open SolarWinds Event Log Consolidator.
     Step 2: Click the Settings tab.                            Step 2: Click the Settings tab.
     Step 3: Click Add Server, and then click Add Server.       Step 3: Select the Server you want to edit, and then click
     Step 4: Enter the server name or IP address.               Edit
     Step 5: Enter a username for a user with administrative Step 4: Modify the servers settings as appropriate.
             privileges.                                        Step 5: If you want to cancel this
           Note: Enter DomainUsername for domain users. procedure, click Results at any time.
     Step 6: Enter and confirm the password for the             Step 6: Click Save to return to the Dashboard view.
     administrative user.
     Step 7: Click Test.
     Step 8: If you want to add another server, click Save &
     Add Another Server and repeat the steps above for                    33 To Delete a Monitored Server
                                                                              Step 1: Select the server you want to delete
     additional servers up to a total of 5 monitored servers.                 on the Settings tab, and then click Delete
     Step 9: If you want to cancel this                                       Server.
     procedure, click Results at any time.
     Step 10: Click Save to return to the Dashboard view.




     CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                             10
Managing Alerts
 Manage alerting and silencing settings for specific Windows events on the Dashboard and Settings tabs.

» Enable alerting for an event to generate a system tray alert and the Alerting icon in SolarWinds Event Log
  Consolidator each time the event occurs.
» Silence events to keep them from showing up in SolarWinds Event Log Consolidator at all. SolarWinds Event Log
  Consolidator applies alerting and silencing based on both the Event ID and source of the selected event.

 11   To Enable Alerting for an Event                          22   To Silence an Event
      Step 1: Open SolarWinds Event Log Consolidator.               Step 1: Open SolarWinds Event Log Consolidator.
      Step 2: Click the Dashboard tab.                              Step 2: Click the Dashboard tab.
      Step 3: Click the light grey icon in the Alerting column      Step 3: Click the dark grey icon in the Silencing column to
      to enable alerting for a specific event from its related      silence a specific event from its related source.
      source.
                                                                    Step 4: Click Yes when asked to confirm your selection.
33    To Manage Alerting & Silencing Settings
      Step 1: Open SolarWinds Event Log Consolidator.
      Step 2: Click on the Settings tab.
      Step 3: Click the Events & Silencing tab.
      Step 4: Click the orange icon in the Alerting column to disable alerting for an event.
      Step 5: Click the light grey icon in the Silencing column to allow SolarWinds Event Log
      Consolidator to resume displaying a silenced event.
     Note: Events for which alerting is enabled by default are highlighted in yellow
           on the Settings > Event Alerts & Silencing tab.
     CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                              11
Editing Servers / Managing Alerts




                  Adding & Editing Servers           Managing Alerts & Silencing Screen



CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                12
Custom Filters
     » Creating Custom Event Filters
        Add and edit custom event filters on the Settings tab. View filtered events on the Dashboard tab.

11   To Create a Custom Filter                                     22 To Edit a Custom Filter
Step 1: Open SolarWinds Event Log Consolidator.                       Step 1: Open SolarWinds Event Log Consolidator.
Step 2: Click the Settings tab.                                       Step 2: Click the Settings tab.
Step 3: Click the Custom Filters tab.                                 Step 3: Click the Custom Filters tab.
Step 4: Click Add Filter.                                             Step 4: Select the filter you want to edit, and then
Step 5: Enter a name for your new filter.                             click Edit.
Step 6: Define the filter's conditions using the menus provided.      Step 5: Modify the filter as appropriate.
Step 7: If you want to add an additional condition, click             Step 6: Click Save.
the Plus button next to an existing condition.
                                                                        33 To View a Custom Filter
       Note: The relationship between multiple conditions is always
"or."                                                                   Step 1: Open SolarWinds Event Log Consolidator.
Step 8: If you want to remove a condition, click the Minus button Step 2: Click the Dashboard tab.
next to the existing condition.                                         Step 3: Select your filter from the filters menu in
Step 9: Click Save.                                                             the upper right corner of the window.
                                                                        Note: This menu indicates the filter that is
 44 To Delete a Custom Filter:
                                                                        currently applied to your events.
      Step 1: Select the filter you want to delete on the Settings
      > Custom Filters tab, and then click Delete Filter.

     CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                              13
Create/ Edit/ Delete Custom Filters




                                                Add, Edit& Delete Custom Event Filters

CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                               14
Helpful Resources
             We invite you to learn more about SolarWinds Free Tools
                                                                                       LEARN MORE




                                                                         Over 1 million IT pros rely on
                                                                         SolarWinds free network monitoring,
                                                                         application monitoring, and storage
                                                                         monitoring tools.



                                                --- Click any of the links above ---
CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                              15
Need more Comprehensive Log
                                              & Event Management?


EXCHANGE SERVER MONITORING SIMPLIFIED
                                               16
Try SolarWinds Log and Event Manager
Event Log Consolidator lets you consolidate and filter your event logs, but what if you
need to do more than that?

SolarWinds Log & Event Manager (LEM)delivers advanced log management capabilities
in a highly affordable, easy-to-deploy appliance.

SolarWinds LEM combines real-time log analysis, event correlation, and a
groundbreaking approach to IT search to deliver the visibility, security, and control you
need to overcome everyday IT challenges.


SolarWinds Log and Event Management can:
»Collect log and event data from tens of thousands of devices.
»Perform real-time event correlation across devices.
»Visualize and explore data easily using advanced IT search.
»Automatically respond to performance issues and mitigate threats using Active
Response technology.


CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                17
Top 5 Reasons to choose SolarWinds for Log &
   Event Management
                   Top 5 Reasons to Download
                      Log & Event Manager


»Collects log & event data from tens of thousands of devices &
performs true real-time correlation

»Powerful Active Response technology enables you to quickly &
automatically take action against threats

»Advanced IT Search employs highly effective data visualization
tools – word clouds, treemaps, & more

»Quickly generates compliance reports for PCI DSS , GLBA, SOX,
NERC CIP, HIPAA, & more

»Out-of-the-box correlation rules, reports, & responses enable
speedy deployment in an hour or less                              --- Click any of the links above ---


  CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                  18
Thank You!




CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE!
                                                19

More Related Content

More from SolarWinds

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilitySolarWinds
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilitySolarWinds
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...SolarWinds
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsSolarWinds
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsSolarWinds
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...SolarWinds
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...SolarWinds
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsSolarWinds
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceSolarWinds
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceSolarWinds
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...SolarWinds
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion SolarWinds
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...SolarWinds
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning SolarWinds
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkSolarWinds
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...SolarWinds
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges SolarWinds
 

More from SolarWinds (20)

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of Observability
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack Observability
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 

Recently uploaded

"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 

Recently uploaded (20)

"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 

Consolidate All Your Event Logs In One Place

  • 1. Consolidate all your Event Logs in one Place! CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 1
  • 2. Agenda » Are Event Logs Important » Event Log Management » SolarWinds Event Log Consolidator  Using the Tool » Helpful Resources » SolarWinds Log & Event Manager CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 2
  • 3. Are Event Logs important? » Event logs on Windows systems are helpful for both troubleshooting when things go wrong and monitoring performance and behavior. » The First thing a System Administrator does to monitor any unusual activity is to check the system log files, it is the first and the most basic step in intrusion detection. » Every time there is a problem with a Windows server SysAdmins start by examining errors in the system and application event logs. » In an occurrence of an intrusion, security log entries can be isolated and preserved. These entries can be valuable during an investigation of the intrusion. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 3
  • 4. Event Log Management » Logging on to each Windows System to see Event Logs is super tiring and cumbersome. » Need to view, consolidate, and dismiss event logs and correlate issues among multiple Windows systems quickly and easily from one central location? » Don’t have a centralized way to view all of your event logs? Here comes a SolarWinds Super Hero…. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 4
  • 5. SolarWinds Event Log Consolidator SolarWinds Event Log Consolidator can not only assist you in organizing all your event logs from Windows Systems in one location but also give you the ability view, and dismiss event logs and » Correlate issues among multiple Windows systems quickly and easily from one central location! » View, consolidate, and dismiss event logs from multiple Windows systems » Filter logs to see data that is important to you! Then, export key data to a .csv file » Enter your device information for up to 5 computers running Windows Server CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 5
  • 6. Adding a Windows Server » To add a Windows server after launching the tool for the first time: Step 1: Enter the server name or IP address Step 2: Enter a username for a user with administrative privileges. Note: Enter DomainUsername for domain users. Step 3: Enter and confirm the password for the administrative user. Step 4: Click Test. Step 5: If you want to add another server, click Save & Add Another Server and repeat the steps above for up to 4 additional servers. Step 6: Click Save to view the Dashboard for your servers. The Dashboard consists of the following sections Total Number of Events: This section shows the number of events for each server in a bar chart. Point to a bar to see detailed information about that server. Event Details: This section shows the details of every event collected by the tool. Click an event to view its details in the lower pane of this section . CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 6
  • 7. Comparing Servers » Comparing Servers Using the Side by Side View Click the Side by Side button on the Dashboard tab to view events from two of your monitored servers in a side-by-side view. This view aligns similar events so you can correlate these events across your selected servers. To use the Side by Side view Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click the Dashboard tab. Step 3: Click Side by Side. Step 4: Modify the time range and choose a filter, and then click Refresh. Step 5: Select the servers you want to view. Step 6: Select or clear the boxes in the column headers to specify what types of values can constitute a correlation between your servers. Step 7: Click Refresh to load new data or apply any changes. Step 8: When you are finished, click Close. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 7
  • 8. Adding/ Comparing Servers Credentials Entering Screen Tool also gives you the ability to view Windows Event logs both graphically over time as well as drill into Specific Events to view the details CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 8
  • 9. Exporting Logs » Exporting Consolidated Logs Click the Export button on the Dashboard tab to export the events that are currently displayed on that tab. To Export Consolidated Log Data Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click the Dashboard tab. Step 3: Modify the time frame, selected servers, or filter to specify what you want to export. Step 4: Click Export. Step 5: Click Browse to browse to the folder in which you want to save the exported file and specify a filename. Note: If you do not specify a folder, the default save location is My Documents. Step 6: Select one of the following export options. Export All Columns: Exports all columns of the data defined by your current Dashboard view in CSV format. Select Columns to Export: Exports selected columns of the data defined by your current Dashboard view in CSV format. Clear a column's check box to omit it from the export. Export To Image: Exports the bar chart from your current Dashboard view in PNG format. Step 7: Click Export. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 9
  • 10. Adding / Editing Servers Add and edit monitored servers on the Settings tab. 11 To Add a New Server 22 To Edit a Monitored Server Step 1: Open SolarWinds Event Log Consolidator. Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click the Settings tab. Step 2: Click the Settings tab. Step 3: Click Add Server, and then click Add Server. Step 3: Select the Server you want to edit, and then click Step 4: Enter the server name or IP address. Edit Step 5: Enter a username for a user with administrative Step 4: Modify the servers settings as appropriate. privileges. Step 5: If you want to cancel this Note: Enter DomainUsername for domain users. procedure, click Results at any time. Step 6: Enter and confirm the password for the Step 6: Click Save to return to the Dashboard view. administrative user. Step 7: Click Test. Step 8: If you want to add another server, click Save & Add Another Server and repeat the steps above for 33 To Delete a Monitored Server Step 1: Select the server you want to delete additional servers up to a total of 5 monitored servers. on the Settings tab, and then click Delete Step 9: If you want to cancel this Server. procedure, click Results at any time. Step 10: Click Save to return to the Dashboard view. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 10
  • 11. Managing Alerts Manage alerting and silencing settings for specific Windows events on the Dashboard and Settings tabs. » Enable alerting for an event to generate a system tray alert and the Alerting icon in SolarWinds Event Log Consolidator each time the event occurs. » Silence events to keep them from showing up in SolarWinds Event Log Consolidator at all. SolarWinds Event Log Consolidator applies alerting and silencing based on both the Event ID and source of the selected event. 11 To Enable Alerting for an Event 22 To Silence an Event Step 1: Open SolarWinds Event Log Consolidator. Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click the Dashboard tab. Step 2: Click the Dashboard tab. Step 3: Click the light grey icon in the Alerting column Step 3: Click the dark grey icon in the Silencing column to to enable alerting for a specific event from its related silence a specific event from its related source. source. Step 4: Click Yes when asked to confirm your selection. 33 To Manage Alerting & Silencing Settings Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click on the Settings tab. Step 3: Click the Events & Silencing tab. Step 4: Click the orange icon in the Alerting column to disable alerting for an event. Step 5: Click the light grey icon in the Silencing column to allow SolarWinds Event Log Consolidator to resume displaying a silenced event. Note: Events for which alerting is enabled by default are highlighted in yellow on the Settings > Event Alerts & Silencing tab. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 11
  • 12. Editing Servers / Managing Alerts Adding & Editing Servers Managing Alerts & Silencing Screen CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 12
  • 13. Custom Filters » Creating Custom Event Filters Add and edit custom event filters on the Settings tab. View filtered events on the Dashboard tab. 11 To Create a Custom Filter 22 To Edit a Custom Filter Step 1: Open SolarWinds Event Log Consolidator. Step 1: Open SolarWinds Event Log Consolidator. Step 2: Click the Settings tab. Step 2: Click the Settings tab. Step 3: Click the Custom Filters tab. Step 3: Click the Custom Filters tab. Step 4: Click Add Filter. Step 4: Select the filter you want to edit, and then Step 5: Enter a name for your new filter. click Edit. Step 6: Define the filter's conditions using the menus provided. Step 5: Modify the filter as appropriate. Step 7: If you want to add an additional condition, click Step 6: Click Save. the Plus button next to an existing condition. 33 To View a Custom Filter Note: The relationship between multiple conditions is always "or." Step 1: Open SolarWinds Event Log Consolidator. Step 8: If you want to remove a condition, click the Minus button Step 2: Click the Dashboard tab. next to the existing condition. Step 3: Select your filter from the filters menu in Step 9: Click Save. the upper right corner of the window. Note: This menu indicates the filter that is 44 To Delete a Custom Filter: currently applied to your events. Step 1: Select the filter you want to delete on the Settings > Custom Filters tab, and then click Delete Filter. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 13
  • 14. Create/ Edit/ Delete Custom Filters Add, Edit& Delete Custom Event Filters CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 14
  • 15. Helpful Resources We invite you to learn more about SolarWinds Free Tools LEARN MORE Over 1 million IT pros rely on SolarWinds free network monitoring, application monitoring, and storage monitoring tools. --- Click any of the links above --- CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 15
  • 16. Need more Comprehensive Log & Event Management? EXCHANGE SERVER MONITORING SIMPLIFIED 16
  • 17. Try SolarWinds Log and Event Manager Event Log Consolidator lets you consolidate and filter your event logs, but what if you need to do more than that? SolarWinds Log & Event Manager (LEM)delivers advanced log management capabilities in a highly affordable, easy-to-deploy appliance. SolarWinds LEM combines real-time log analysis, event correlation, and a groundbreaking approach to IT search to deliver the visibility, security, and control you need to overcome everyday IT challenges. SolarWinds Log and Event Management can: »Collect log and event data from tens of thousands of devices. »Perform real-time event correlation across devices. »Visualize and explore data easily using advanced IT search. »Automatically respond to performance issues and mitigate threats using Active Response technology. CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 17
  • 18. Top 5 Reasons to choose SolarWinds for Log & Event Management Top 5 Reasons to Download Log & Event Manager »Collects log & event data from tens of thousands of devices & performs true real-time correlation »Powerful Active Response technology enables you to quickly & automatically take action against threats »Advanced IT Search employs highly effective data visualization tools – word clouds, treemaps, & more »Quickly generates compliance reports for PCI DSS , GLBA, SOX, NERC CIP, HIPAA, & more »Out-of-the-box correlation rules, reports, & responses enable speedy deployment in an hour or less --- Click any of the links above --- CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 18
  • 19. Thank You! CONSOLIDATE ALL YOUR EVENT LOGS IN ONE PLACE! 19