<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Windows Event Collection</title>
	<atom:link href="http://www.zhen.org/blog/2004/10/05/windows-event-collection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zhen.org/blog/2004/10/05/windows-event-collection/</link>
	<description>Business, Technology and Other Things</description>
	<pubDate>Tue, 06 Jan 2009 05:12:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Jim B.</title>
		<link>http://www.zhen.org/blog/2004/10/05/windows-event-collection/#comment-122</link>
		<dc:creator>Jim B.</dc:creator>
		<pubDate>Tue, 25 Jan 2005 18:18:07 +0000</pubDate>
		<guid isPermaLink="false">/?p=9#comment-122</guid>
		<description>jlz,

You might be interested in log analysis using SEC- The Simple Event Correlator.  Part II of the article at
http://sixshooter.v6.thrupoint.net/SEC-examples/article.html
describes using SEC for these situations.

Best Regards,
Jim B.</description>
		<content:encoded><![CDATA[<p>jlz,</p>
<p>You might be interested in log analysis using SEC- The Simple Event Correlator.  Part II of the article at<br />
<a href="http://sixshooter.v6.thrupoint.net/SEC-examples/article.html" rel="nofollow">http://sixshooter.v6.thrupoint.net/SEC-examples/article.html</a><br />
describes using SEC for these situations.</p>
<p>Best Regards,<br />
Jim B.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jlz</title>
		<link>http://www.zhen.org/blog/2004/10/05/windows-event-collection/#comment-77</link>
		<dc:creator>jlz</dc:creator>
		<pubDate>Thu, 06 Jan 2005 22:51:03 +0000</pubDate>
		<guid isPermaLink="false">/?p=9#comment-77</guid>
		<description>Parag,

That's a great list.

I would also be interested in 

- successful logins during odd hours
- login/off patterns over time (week, month, etc) to detect abnormal behaviors
- who's accessed what resource (files, appliacations) for security purposes as well as utilization trending (say this is a shared citrix server or something)

Lots of operational as well as security type of reporting and alerting. I would be very interested in other thoughts.</description>
		<content:encoded><![CDATA[<p>Parag,</p>
<p>That&#8217;s a great list.</p>
<p>I would also be interested in </p>
<p>- successful logins during odd hours<br />
- login/off patterns over time (week, month, etc) to detect abnormal behaviors<br />
- who&#8217;s accessed what resource (files, appliacations) for security purposes as well as utilization trending (say this is a shared citrix server or something)</p>
<p>Lots of operational as well as security type of reporting and alerting. I would be very interested in other thoughts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: parag Deshpande</title>
		<link>http://www.zhen.org/blog/2004/10/05/windows-event-collection/#comment-76</link>
		<dc:creator>parag Deshpande</dc:creator>
		<pubDate>Thu, 06 Jan 2005 22:05:27 +0000</pubDate>
		<guid isPermaLink="false">/?p=9#comment-76</guid>
		<description>When I consider Security log analysis for win2k server i think rules that should set are 
- Any Start up or shut down or server or any new services should have proper authorization. 
- Windows server develops logs of logs cleaning is often done to use the disk space, If the logs cleared for this purpose, it should done with proper change control procedure i.e. Authorization , Backup/ Archival , Storage .
- Analysis of warnings and failure audits for security sensitive events ( Analysis not from Performance or trouble shooting perspective)
- Failed logins (Expected to have warning event for this)
Am I missing some thing...please let me know....

Parag</description>
		<content:encoded><![CDATA[<p>When I consider Security log analysis for win2k server i think rules that should set are<br />
- Any Start up or shut down or server or any new services should have proper authorization.<br />
- Windows server develops logs of logs cleaning is often done to use the disk space, If the logs cleared for this purpose, it should done with proper change control procedure i.e. Authorization , Backup/ Archival , Storage .<br />
- Analysis of warnings and failure audits for security sensitive events ( Analysis not from Performance or trouble shooting perspective)<br />
- Failed logins (Expected to have warning event for this)<br />
Am I missing some thing&#8230;please let me know&#8230;.</p>
<p>Parag</p>
]]></content:encoded>
	</item>
</channel>
</rss>
