Security Basics mailing list archives

Re: SQL Queries of Windows Event Logs


From: Adam Jones <ajones1 () gmail com>
Date: Wed, 8 Jun 2005 08:17:33 -0500

How are you importing those into the database? Given some idea of the
table structure you have it would be easier for someone to come up
with queries that would fit the bill. I have no real experience with
mssql, so I might not be much help there, but providing people with a
concept of your table structure would help a lot.

-Adam

On 6/6/05, Joe Quigley <jquigley () iir-central com> wrote:

Hello Everyone,


I've started importing all our windows event logs into a MSSQL database
and now need to write the queries for reporting. Since SQL is not my
strong point, I'd like to ask the list if anyone has seen (or would be
willing to share) a recommended set of reports/queries for tracking
potential security issues (failed logins, AD object changes, etc).

Thanks in advance for any and all help,

Joe


Current thread: