Thinking about using the Windows Event Logs as my main log store - looking for pros and cons

I have been writing some larger scripts that write to physical log files.  Until today I have avoided trying to use the Windows Event logs, but, am beginning to rethink this and wondered if anyone has done this, and, what the strengths and weaknesses
of this logging approach has been.  If I do it, I will probably write a function that accepts pipelined input and simply pass output to the log.  I wanted to get a feel for what I would be getting into before I started writing things up since this
will probably take a little bit of work to get set up to run properly.

At my company we use the Windows event log for many of our batch process logging for several reasons:
Unlike logging to a central database, the Windows event log is always available. I've seen poorly thought out logging solution which log to a database and if the database happens to be unavailable the batch process would fail.
Monitoring tool such as SCOM already have Windows event log watchers so adding alerts to take action based on message written to the Windows event log is easy
Built-in support for writing Windows event log entries in the Powershell V2 write-eventlog cmdlet, a simple CLR can created in SQL Server or even command-line eventcreate.exe
Easy to create a custom event log so you don't have to use the default application log in Windows 2008 and higher.
Most shrink-wrap S/W already use the event log
Issues I've seen:
Windows 2008 with UAC on requires "registering" i.e. creating a new event log source with UAC. This can be done one time manually. Unfortunately there isn't a way to automate UAC--pure GUI. The Powershell command would be "New-EventLog -LogName Application
-Source  mysource" if you're using the Application log and must be run as  administrator.
Errant process writes many entries to the event log. Depending on the volume like for example writing stack dumps this can performance problems. I  think I recall an issue an Windows 2003 or Windows 2008 with UAC off  if you're creating a new
event log source each time (which you shouldn't) then these results in many registry entries which can cause problems.
I don't think the issues outweigh the benefits--just something to be aware of.

Similar Messages

  • Hi, i wanted to resize my windows partion. I was thinking of using the default backup system for windows. Then switching to mac partion, deleting the bootcamp and then restoring a new enlarged partion from the backup. Is this possible?

    hi,
    i wanted to resize my windows partition. I was thinking of using the default backup system for windows. Then switching to mac partion, deleting the bootcamp and then restoring a new enlarged partition from the backup. Is this possible?

    I see youhave gotten recommendatons for using WinClone or CampTune.  I have used both and they both work well.
    You have asked about using the WIndows 7 utility to backup your drive and restor it onto a larger partition.  I will tell you fro experience that this will probably not do what you want, and may do something that you don't want.  You can use the Windows 7 native backup tool to make a backup of your Windows 7 partition.  It will most liekly end-up making a dive image of the whole drive.  When yourestore that backup, it will try to re-create teh partitions of exactly the same size as they were when the backup was taken, so it won't increase your partition size for you.  Worse, since Windows doesn't natively know how to read./write HFS+ volumes, the backup will make a partition for your MacOS (replacing any you may have now), except that the copy restored by WIndows will be totally worthless, and you will not be able to boot MacOS from it, or even read it under MacOS.
    Now I will tell you that I've also had some fairly good success working with the free tool CloneZilla.  Since it hasn't been mentioned yet, and everything else mentioned does cost you money, I thought I would throw it out.  CloneZilla is not as easy to use as the tools mentioned, but it has worked for me int hte past, so it is something to consider.  I tend to use CampTune myself, but that was because I purchased a bundle deal for them and it was included in that deal.

  • Pros and cons of using email sending package in oracle 8.1.6

    hi ,
    i would like to know the advantages /disadvantages of using email sending package from oracle 8.1.6
    compared to sending the same using say perl or php.
    iam developing a site in php/oracle8.1.6 , in which iam supposed to create a payement module.whenever a user
    register(for free trial or subscribing the site) i'll have to send him a welcoming mail.In addition to this iam also supposed to find out wether subscribers are paying cash at right time and if not send them reminder mails and other for related scenarios . i can do the same in Perl or PHP.but if iam not gaining much(say based on server performance or load) then i think i can go ahead with oracle package. when i tested it i found that its slow . what about the load that it may cause for the server (ours is linux ).
    please do give inputs on this

    Hi Ravi,
    Thanks for your reply.
    But I am specifically looking at pros and cons for web services. So the thread which you passed to me won't help.
    Regards
    Nitin.

  • I am setting up a lab of imacs in a school.  I have successfully bound the imacs to our network and can log in using the windows account.  However, I cannot access my files.  Is there another step?

    I am setting up a lab of imacs in a school.  Our network is windows based using active directoy.  I have successfully bound the imacs to our network and can log in using the windows account.  However, I cannot access my files.  Is there another step?

    If the modem is also a router, either use the modem in bridge and run pppoe client on the TC.. that is assuming ADSL or similar eg vdsl. If it is cable service.. and the modem is a router, then bridge the TC.. go to internet page and select connect by ethernet and below that set connection sharing to bridge.
    Please tell us more about the modem if the above gives you issues.

  • Operations Manager Failed to Access the Windows Event Log and management server is showing warning state

    Hi,
    I am monitoring AD server from SCOM 2012 R2. My management server goes into waning state. When i run Health explorer then it come back in the healthy state but after some time it again goes into warning state. After seeing alert i found that a alert is coming
    again and again i.e.  Operations Manager Failed to Access the Windows Event Log.The description of alert is mention below
    The Windows Event Log Provider is still unable to open the DhcpAdminEvents event log on computer 'nc2vws12ad5.corp.nathcorp.com'.
    The Provider has been unable to open the DhcpAdminEvents event log for 64080 seconds.
    Most recent error details: The RPC server is unavailable.
    Please suggest me how to resolve this so that my management server will again come back in healthy state.
    Thanks
    Abhishek

    Hi Abhishek,
    As i mentioned earlier the Alert resolution says the same points.
    Can you give details on the below ?
    Is there really a log named "Dhcpadminevents" in the MS's Event viewer ?
    Did you recently configure any new alert where you mentioned "Dhcpadminevents"
    as a event log location ?
    If yes then what is the target you selected for the rule / monitor there ?
    Can you post the results for analysis ?
    Gautam.75801

  • Hi,   I am trying to find out a bit more about creative cloud...  I currently use PS5 extended...  I have it on my desk top at home but travel often and use a pc. which does not have PS5 because it is licensed to mac...  So i am now thinking of using the

    hi,   I am trying to find out a bit more about creative cloud...  I currently use PS5 extended...  I have it on my desk top at home but travel often and use a pc. which does not have PS5 because it is licensed to mac...  So i am now thinking of using the cloud...  will i be able to use it on both computers? and will it work if there is slow or no internet?.

    Here are some links to general information.  IF you have specific questions feel free to ask...
    Creative Cloud Learn & Support
    http://helpx.adobe.com/creative-cloud.html
    Creative Cloud / Common Questions
    http://helpx.adobe.com/creative-cloud/faq.html
    Creative Cloud Plans
    https://creative.adobe.com/plans

  • I am thinking about purchasing the CC for Photography monthly plan. Will I be able to use Lightroom Presets that I have already purchased previously?

    I have Lightroom 4 and Photoshop CS2. I am thinking about getting the monthly plann for CC. I just wanted to know if I can use all the Lightroom Presets and Photoshop Actions that I have already purchased?

    Yes, they will transfer across to the new version of Lr when you install it.

  • Thinking about using Time Machine for the first time...

    I just assume that updates are inherently good to have, regardless of what it's for. I figure that the developers know a lot more than I do regarding the optimization or improvement of their own software, so I simply allow their download. I'm thinking about using my Time Machine for the first time and reverting back to the pre-9.1 install, if that's even possible. Things were working fine for me and now there are all kinds of issues with communication between my Axiom Pro 61 and Logic. Nothing responds through Hypercontrol anymore, and I don't expect any updates from M-Audio until at least 2012. Anyone else thinking about taking this route?

    Yes, I did. I opened that version immediately after I discovered that 9.1 had that effect and the controller was still inoperative. Of course, I still have MIDI input and PB/Mod wheel control, but that's about it. Everything else would need to be manually loaded, which the Pro series is supposed to do automatically. I haven't restarted my iMac yet, nor have I tried removing the keyboard from the computer altogether and perhaps reconnecting it. Maybe that would reset it...

  • Thinking about switching to Windows

    This is not meant to be a Os X vs Windows thread. I dont think one platform is better than the other, but they have different strengths and weaknesses. What I want to hear is what kind of pitfalls I can expect in regards to live video performance if I go down the Windows way.
    Reason I`m asking is:
    My Macbook Pro recently died, so I borrowed my friends HP Laptop with similiar specs. He has used it alot for music production, sound of movies etc, and quite a decent graphics card (6xxxm 1gb ati radeon) I wanted to connect a Matrox Dualhead2go to two 1280 x 800 projectors using Resolume. However, I encountered nothing but problems all the way. Couldnt dual monitor resolutions, display went black, drivers stopped working, program had to restart. When it worked, it worked well, but I think I aged 10 years during that gig.
    Before that I wanted to buy a stationary shuttle PC, top of the line, 7970 radeon 3gb, Ivy bridge, Dell Touch Screen etc, but now I got a little scared of doing the switch.Having used Macbook Pro`s ever since I started VJìng, I`m very much used to plug and play using Triplehead2go, it just works. I usually use crossplatform software (resolume, after effects) but I also use motion and modul8 from time to time. I can live without however. The simplest choice is to buy a Macbook Pro, I know it, it works. But I like the idea of multiple choices in hardware, the ability to make a semi transportable shuttle and to be able to connect 6 projectors using eyefinity as some promoters have asked me to do bigger shows. Portability is important, but since I drag around 3 + projectors, the extra 10kg`s is not so important.
    So to all Windows VJ`s out there (or people with experience from both platforms) what kind of headaches can I expect if I make the switch? I`m a quite tech savvy guy (learn fast) even though I dont have much experience with the windows platform.
    1. Do you experience driver issues and troubles related to that?
    2. I`m not dependant of Syphon, but I would love to see a Windows version eventually. Do you think that is likely to happen during the next couple of years?
    3. Blue Screen of death or other strange issues?
    4. I have always wanted to get into Quartz Composer to create patches and effects for Resolume, but is there a equavilent Windows version?
    5. I`ve always been drooling over this one: http://www.youtube.com/watch?v=WxvQw0GVH2c, which is one reason I always wanted a PC.
    6. Slower performance over time using Windows? Or is that a thing of the past?
    7. Is the Os X video engine better than the one Windows is using?
    8. Any video software for windows that currently doesnt work in os x?
    9. Can you predict the future? is Apple leaving the pro market? Is Windows on a comeback?
    Hope this post is clear enough. I`m asking what I`m likely to miss out on, what I can expect, what headaches and what new possibilities comes with changing from Mac Os X to Windows. As my computer broke, now is the time for change, if ever. Hope to get some constructive replies guys!
    - Mads

    Mads Meskalin wrote:
    Hope to get some constructive replies guys!
    - Mads
    Good luck, but I doubt that you will. This is a Mac user forum; your questions are about Windows and would be better suited to a Windows forum.
    As for Q9, the moderators have a habit of removing posts that speculate about Apple's future direction.

  • Vista: use the windows program manager to execute operating system commands

    attempting to run forms 6 on vista... the forms app attempts a call sqlplus using the host builtin to populate some tables before calling the report.
    in windows vista i get a message box indicating "use the windows program manager to execute operating system commands".
    is this windwos vista message? would this have to do with permissions?
    any insight most appreciated and thanks in advance.

    I don't know about the HOST-problem, but..
    the forms app attempts a call sqlplus using the host builtin to populate some tables before calling the report.What about putting the logic from the SQL*Plus-scripts into a database-procedure and call that instead. I think,, with the current approach you will get problems at least when you have to migrate to Web (e.g. Forms 10g).

  • How to use the windows key (super or hiper) as a keystroke modifier?

    I can associate the windows key (KeyEvent.VK_WINDOWS) as a regular key on a KeyStroke without problem.
    It can be alone or with a modifier, like CTRL+WIN
    KeyStroke.getKeyStroke( KeyEvent.VK_WINDOWS, InputEvent.CTRL_DOWN_MASK )My doubt is: Is there a way to use it as a modifier?
    In other words, is it possible to create the KeyStroke using the windows key with any other? e.g. "WIN+K"
    Thanks,
    Henrique Abreu

    Thanks a lot for the quick answer.
    Your KeyboardCommands class doesn't do it (but gives the idea), because it can only trigger an action on one key (like KeyStroke, that handles key+modifier).
    I could make big changes on it to add the functionality of triggering an event on a combination of keys, which would solve my problem.
    Although this solution is not so good because we totally give up of actions in Swing, which I mean stuff like actionMaps, InputMaps WHEN_ANCESTOR_OF_FOCUSED_COMPONENT, etc.
    If KeyStroke class really doesn't provide this (unbelievable!), I wonder if there is a way to extend and enhance it? (or AWTKeyStroke)
    Can anyone say if its possible, before I go deep and find out that it isn't?
    Another secondary question (that I think doesn't worth a new topic), what's the META_DOWN_MASK or META_MASK? or where is this key?
    Henrique Abreu

  • Set a timeout for crystal sessions while using the Windows.Forms.Viewer?

    Hi,
    I am looking for a way to set the timeout for the crystal report sessions when using the Windows.Forms.Viewer in a .NET application. I guess that the default value is 20 minutes (like in the entperprise installations) but we cannot afford to keep many sessions open for that long. Is there a registry entry which can be set? Or even a way to do this programmatically?
    Thank you in advance,
    Stratos

    Hi David,
    we are talking here about a standalone .NET application where the reports are installed locally (like the application itself). We are not retrieving the reports from a server. The whole thing was developed using the crystal report viewer model probably because it was easier to do so. Is there a method in this model to tell the crystal runtime to do the clean-up work either for a report (like the ReportDocument.Close() ) or for the entire runtime instance. Dispose() does not seem to help us. If you say that there is no other way than redesign then we have to consider this option also.
    Cheers
    Stratos
    PS: What I was thinking of (as Plan B instead of using the ReportDocument object model) is to instantiate the crystal report viewer object in a separate process (.exe). Please note that we open a new crystal report viewer windows for each report, which is displayed. Closing the viewer window (ie. terminate the process) will at least then clean up and release the crystal DLLs and hopefully close the database connections. Or am I missing something here?
    Edited by: Efstratios Karaivazoglou on Jul 29, 2008 10:05 PM

  • Thinking about using Mac Mini's as desktops for 20 employee business.  Pro's Vs. Con's

    Thinking about using Mac Mini's as desktops for 20 employee business.  Pro's Vs. Con's

    Your best bet would be to buy a single 2012 MacMini Server model that you can use to manage the balance of the other machines. Either that or upgrade one of the MM's to OS X Yosemite Server . You can find information about the Server edition at:
    https://www.apple.com/osx/server/
    However I would STRONGLY recommend visiting your local Apple Store and ask to speak to their business specialist, they are trained to manage customer needs such as yours.
    The major advantage of using Macs over any PC is the stability of OS X itself and the overall quality of support that you will never get with HP.

  • How to use the windows API GetCaretPos with FireFox? It works with IE

    I want to get caret position from a windows desktop application using the Windows API GetCaretPos. It works in any windows Application and in IE. It worked also in FireFox for some minutes in version 3.6.8 but than it stopped working. Can anyone tell me how to make it work?
    == This happened ==
    Every time Firefox opened

    Many site issues can be caused by corrupt cookies or cache. In order to try to fix these problems, the first step is to clear both cookies and the cache.
    Note: ''This will temporarily log you out of all sites you're logged in to.''
    To clear cache and cookies do the following:
    #Go to Firefox > History > Clear recent history or (if no Firefox button is shown) go to Tools > Clear recent history.
    #Under "Time range to clear", select "Everything".
    #Now, click the arrow next to Details to toggle the Details list active.
    #From the details list, check ''Cache'' and ''Cookies'' and uncheck everything else.
    #Now click the ''Clear now'' button.
    Did this fix your problems? Please report back to us!

  • Yooooooooooooooo, Thinking about getting the K7N2

    Im thinking about buying the K7n2 nforce2 mobo. Is it a fast mobo, Stable, good temp readings any issues?
    Any information would be appreciated. this mobo looks NICEEE!!!! :D  :D  :D
                                           --Rob--

    Hi !
    I installed it this weekend with my old CPU, and have a few notes about it  :D
    First of all the pleasant setup:
    No problems setting up the board with the old installation of Win XP (yes I know.. you should not do that, but I did not have the time for reinstallation)
    Only driver I had to install was the very debated IDE driver.
    The things that comes to mind compared to 420D:
    - Very crisp sound - even better (and who have thougt that was possible)
    - Faster Windows boot
    - In general better speed & stability.
    The only benchmarks I had time to complete was 3D mark 2001:
    MSI GeForce 4 MX440 8X
    http://service.madonion.com/compare?2k1=5264530
    MSI GeForce 4 Ti4200 8X
    http://service.madonion.com/compare?2k1=5271508
    This should be OK with an old Win XP installation.
    However the lack of SATA, RAID & Firewire is pulling me to "The Dark side" unless of course the new boards in January have theese features and a good pricing.
    My old setup:
    nForce 420D o/b graphics
    Athlon XP1700+
    2X Samsung 256MB PC2100 DDR
    My new setup: (for now at least)
    K7N2-L
    Athlon XP1700+
    256MB Buffalo PC3200 DDR
    MSI GF4 Ti4200 8X

Maybe you are looking for