<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows 2003 / 2008 event logging to Syslog</title>
	<atom:link href="http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/</link>
	<description>IT professional, Formula 1 addict, security/hacking enthusiast, I love LAMP</description>
	<lastBuildDate>Tue, 07 Feb 2012 22:28:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Chris Provolt</title>
		<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/comment-page-1/#comment-3126</link>
		<dc:creator>Chris Provolt</dc:creator>
		<pubDate>Thu, 24 Mar 2011 20:19:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.ashleyknowles.net/?p=3#comment-3126</guid>
		<description>On the point of using group policy to configure windows for auditing one could always use security filtering. Create a security group add the workstations / servers you want monitored to it. Create the audit policy and add the group you created for apply and do not apply to any other group like authenticated users. Link the policy at a level in your ou structure that would encompass the systems that were added to the group and you are on your way to centralized audit configuration.</description>
		<content:encoded><![CDATA[<p>On the point of using group policy to configure windows for auditing one could always use security filtering. Create a security group add the workstations / servers you want monitored to it. Create the audit policy and add the group you created for apply and do not apply to any other group like authenticated users. Link the policy at a level in your ou structure that would encompass the systems that were added to the group and you are on your way to centralized audit configuration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashley Knowles</title>
		<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/comment-page-1/#comment-1565</link>
		<dc:creator>Ashley Knowles</dc:creator>
		<pubDate>Thu, 20 Jan 2011 00:20:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.ashleyknowles.net/?p=3#comment-1565</guid>
		<description>Just a bit of Aussie slang maybe? I certainly won&#039;t claim that as my own =P</description>
		<content:encoded><![CDATA[<p>Just a bit of Aussie slang maybe? I certainly won&#8217;t claim that as my own =P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/comment-page-1/#comment-1563</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 19 Jan 2011 20:10:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.ashleyknowles.net/?p=3#comment-1563</guid>
		<description>Good information and well written. Is cracking a darky an old expression or did you make that up (it cracked me up).</description>
		<content:encoded><![CDATA[<p>Good information and well written. Is cracking a darky an old expression or did you make that up (it cracked me up).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle During</title>
		<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/comment-page-1/#comment-962</link>
		<dc:creator>Kyle During</dc:creator>
		<pubDate>Mon, 22 Nov 2010 10:49:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.ashleyknowles.net/?p=3#comment-962</guid>
		<description>Nice thoughts. I like your web design also. Keep up your good work.</description>
		<content:encoded><![CDATA[<p>Nice thoughts. I like your web design also. Keep up your good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wes</title>
		<link>http://www.ashleyknowles.net/2009/10/windows-2003-2008-event-logging-to-syslog/comment-page-1/#comment-165</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Thu, 08 Apr 2010 23:38:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.ashleyknowles.net/?p=3#comment-165</guid>
		<description>I&#039;ve used these same combination of tools with success. I&#039;m currently getting some glitches with 2008 x64, but expect it to be ironed out shortly.

However, while we do have Kiwi Syslog in action, I&#039;m utilizing Splunk to be the aggregatore for Windows logs - so that others can get to a web page and do regular expression searches for what they want to see. That&#039;s handy when you have developers to support and don&#039;t want to give them access directly to the server logs. They can search just by the machine and some text, and get what they want. However, I hear some negative things about the latest version of Splunk and am staying on my older version for awhile.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve used these same combination of tools with success. I&#8217;m currently getting some glitches with 2008 x64, but expect it to be ironed out shortly.</p>
<p>However, while we do have Kiwi Syslog in action, I&#8217;m utilizing Splunk to be the aggregatore for Windows logs &#8211; so that others can get to a web page and do regular expression searches for what they want to see. That&#8217;s handy when you have developers to support and don&#8217;t want to give them access directly to the server logs. They can search just by the machine and some text, and get what they want. However, I hear some negative things about the latest version of Splunk and am staying on my older version for awhile.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

