Creating a custom view for windows log based on a "Contains {text}" rule

Posted by jussinen on Server Fault See other posts from Server Fault or by jussinen
Published on 2012-04-02T09:58:59Z Indexed on 2012/04/02 11:33 UTC
Read the original article Hit count: 207

I have a server running Windows Server 2008.

I'm using Windows Server Auditing to check when and by which user a folder is modified to determine who is modifying it as the modifications are causing problems.

I can see the log of the audit when a change is made in the System log.

How do I create a Custom View that will return all events from System log where a certain text (which is the folder name) is present? The create custom view doesn't seem to have that option.

I'm not sure whether it's possible via custom xml query or whether I'll need to export the system log to csv and search in Excel.

John

© Server Fault or respective owner

Related posts about windows-server-2008

Related posts about windows-server