<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Guerrilla Event Log archiving: why and how.</title>
	<atom:link href="http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 06:08:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Natasha-web</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-11128</link>
		<dc:creator>Natasha-web</dc:creator>
		<pubDate>Wed, 16 Dec 2009 04:50:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-11128</guid>
		<description>precitat cely blog, docela dobrej</description>
		<content:encoded><![CDATA[<p>precitat cely blog, docela dobrej</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10616</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Tue, 16 Jun 2009 19:49:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10616</guid>
		<description>Thanks for following up Joe!

I am looking at some plugins for windows live writer that format code properly... I will let you know how it goes! 

We would love to see some new Admin&#039;s Arsenal posts :)</description>
		<content:encoded><![CDATA[<p>Thanks for following up Joe!</p>
<p>I am looking at some plugins for windows live writer that format code properly&#8230; I will let you know how it goes! </p>
<p>We would love to see some new Admin&#8217;s Arsenal posts :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rever75</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10613</link>
		<dc:creator>Rever75</dc:creator>
		<pubDate>Mon, 15 Jun 2009 20:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10613</guid>
		<description>Thanks for the reply this script is awesome. I no longer get the error message but oddly it will create the directory on my File Server but never places the backed up logs in it.</description>
		<content:encoded><![CDATA[<p>Thanks for the reply this script is awesome. I no longer get the error message but oddly it will create the directory on my File Server but never places the backed up logs in it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JoeG</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10612</link>
		<dc:creator>JoeG</dc:creator>
		<pubDate>Mon, 15 Jun 2009 20:11:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10612</guid>
		<description>Oh and an interesting note here; the error was actually on like 151, however (for reasons known only to Microsoft) when the VBScript interpreter catches an error in a function, it lists the line number where the Function breaks, not necessarily where the problem is.</description>
		<content:encoded><![CDATA[<p>Oh and an interesting note here; the error was actually on like 151, however (for reasons known only to Microsoft) when the VBScript interpreter catches an error in a function, it lists the line number where the Function breaks, not necessarily where the problem is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JoeG</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10611</link>
		<dc:creator>JoeG</dc:creator>
		<pubDate>Mon, 15 Jun 2009 20:08:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10611</guid>
		<description>Ok, so There is a formatting error here. I believe that I can tract the error to a pervious version of Wordpress, because I was able to correct it on my blog.

Just in case I&#039;ve also taken a screenshot of the offending function, as it should appear. Here is a link to the post where I&#039;ve fixed it: http://www.laoae.com/2008/11/guerrilla-event-log-archiving-why-and-how/

Now then, apologies to all that have had issues with this script (apparently this is the most popular post I&#039;ve ever written, as I&#039;ve had commentary on this issue from several different sources), my bad for not vetting it after it was posted.

I&#039;m working on a better way of posting code to Wordpress so that this doesn&#039;t happen in the future.</description>
		<content:encoded><![CDATA[<p>Ok, so There is a formatting error here. I believe that I can tract the error to a pervious version of WordPress, because I was able to correct it on my blog.</p>
<p>Just in case I&#8217;ve also taken a screenshot of the offending function, as it should appear. Here is a link to the post where I&#8217;ve fixed it: <a href="http://www.laoae.com/2008/11/guerrilla-event-log-archiving-why-and-how/" rel="nofollow">http://www.laoae.com/2008/11/guerrilla-event-log-archiving-why-and-how/</a></p>
<p>Now then, apologies to all that have had issues with this script (apparently this is the most popular post I&#8217;ve ever written, as I&#8217;ve had commentary on this issue from several different sources), my bad for not vetting it after it was posted.</p>
<p>I&#8217;m working on a better way of posting code to WordPress so that this doesn&#8217;t happen in the future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rever75</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10610</link>
		<dc:creator>Rever75</dc:creator>
		<pubDate>Mon, 15 Jun 2009 14:26:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10610</guid>
		<description>I added the second And since it would error with and Expected &#039;Then&#039; until I added it.</description>
		<content:encoded><![CDATA[<p>I added the second And since it would error with and Expected &#8216;Then&#8217; until I added it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rever75</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10609</link>
		<dc:creator>Rever75</dc:creator>
		<pubDate>Mon, 15 Jun 2009 14:25:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10609</guid>
		<description>Ok can get it to archive all the Event Logs, clear them and create the directory on the Remote machine but not copy the actual logs. I was getting errors at line 149 or 150 until I removed this part from line 150. 
   And UCase( strSourceFolder) And UCase( strTargetFolder)

After that all worked except the actual copying of the file.</description>
		<content:encoded><![CDATA[<p>Ok can get it to archive all the Event Logs, clear them and create the directory on the Remote machine but not copy the actual logs. I was getting errors at line 149 or 150 until I removed this part from line 150.<br />
   And UCase( strSourceFolder) And UCase( strTargetFolder)</p>
<p>After that all worked except the actual copying of the file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rever75</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-10608</link>
		<dc:creator>Rever75</dc:creator>
		<pubDate>Mon, 15 Jun 2009 13:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-10608</guid>
		<description>I am getting an issue at Line 150 Char 41 Expected &#039;Then&#039; looks like it is not excepting the 2 Ucases</description>
		<content:encoded><![CDATA[<p>I am getting an issue at Line 150 Char 41 Expected &#8216;Then&#8217; looks like it is not excepting the 2 Ucases</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9085</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Tue, 25 Nov 2008 20:10:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9085</guid>
		<description>Thanks Joe! I will throw your link into the post for reference. And will take a look at the css.</description>
		<content:encoded><![CDATA[<p>Thanks Joe! I will throw your link into the post for reference. And will take a look at the css.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Glessner</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9084</link>
		<dc:creator>Joe Glessner</dc:creator>
		<pubDate>Tue, 25 Nov 2008 18:37:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9084</guid>
		<description>Karl,

As I noted below, the formatting is not showing up correct on this post in FireFox (I&#039;m thinking there is something that needs to be tweaked in the CSS for this page.

I could correct it by making the font smaller with some HTML tags, but then on the IE page it would be tiny and unreadable ;)</description>
		<content:encoded><![CDATA[<p>Karl,</p>
<p>As I noted below, the formatting is not showing up correct on this post in FireFox (I&#8217;m thinking there is something that needs to be tweaked in the CSS for this page.</p>
<p>I could correct it by making the font smaller with some HTML tags, but then on the IE page it would be tiny and unreadable ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Glessner</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9083</link>
		<dc:creator>Joe Glessner</dc:creator>
		<pubDate>Tue, 25 Nov 2008 18:34:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9083</guid>
		<description>By any chance are you viewing the post in Firefox? The reason I ask, is that for some odd reason when I view this page in FF the formatting is broken, and some of the lines wrap (in scripts this is very bad).

If you look around line 150 in the script on this page in Firefox, you&#039;ll notice that there is a &quot;then&quot; just floating (got pushed down by word wrap).

Now if you copy that, it may retain the odd formatting in your text editor. You can find this post on my blog at http://joeit.wordpress.com/2008/11/10/guerrilla-event-log-archiving-why-and-how/, with correct formatting.

As to the line of code you call out: 
DIM objDir1: objDir1 = “\\” &amp; strComputer &amp; “\c$\EVT”

This creates a variable that allows the script to create a temporary directory on the remote machine for the event logs to be exported to (the Windows EventLog API security prevents you making copies of the event logs to remote machines directly, all copies must be saved locally or not at all).

objDir2 on the other hand is the destination of the files after then have been copied to objDir1 (basically objDir1 is on whatever machine you run this against, and objDir2 is the final destination for the files).

Hope that gets you where you need to be!</description>
		<content:encoded><![CDATA[<p>By any chance are you viewing the post in Firefox? The reason I ask, is that for some odd reason when I view this page in FF the formatting is broken, and some of the lines wrap (in scripts this is very bad).</p>
<p>If you look around line 150 in the script on this page in Firefox, you&#8217;ll notice that there is a &#8220;then&#8221; just floating (got pushed down by word wrap).</p>
<p>Now if you copy that, it may retain the odd formatting in your text editor. You can find this post on my blog at <a href="http://joeit.wordpress.com/2008/11/10/guerrilla-event-log-archiving-why-and-how/" rel="nofollow">http://joeit.wordpress.com/2008/11/10/guerrilla-event-log-archiving-why-and-how/</a>, with correct formatting.</p>
<p>As to the line of code you call out:<br />
DIM objDir1: objDir1 = “\\” &amp; strComputer &amp; “\c$\EVT”</p>
<p>This creates a variable that allows the script to create a temporary directory on the remote machine for the event logs to be exported to (the Windows EventLog API security prevents you making copies of the event logs to remote machines directly, all copies must be saved locally or not at all).</p>
<p>objDir2 on the other hand is the destination of the files after then have been copied to objDir1 (basically objDir1 is on whatever machine you run this against, and objDir2 is the final destination for the files).</p>
<p>Hope that gets you where you need to be!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9081</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 25 Nov 2008 15:44:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9081</guid>
		<description>I just highlighted it all and put it in notepad. Looks like it copied fine.  I even tried ultraedit.  Maybe I could just get your copy?  I also don&#039;t understand the config, mostly this part:

DIM objDir1: objDir1 = &quot;\\&quot; &amp; strComputer &amp; &quot;\c$\EVT&quot;

I already had set the path at the objDir2 variable.</description>
		<content:encoded><![CDATA[<p>I just highlighted it all and put it in notepad. Looks like it copied fine.  I even tried ultraedit.  Maybe I could just get your copy?  I also don&#8217;t understand the config, mostly this part:</p>
<p>DIM objDir1: objDir1 = &#8220;\\&#8221; &amp; strComputer &amp; &#8220;\c$\EVT&#8221;</p>
<p>I already had set the path at the objDir2 variable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9080</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Tue, 25 Nov 2008 15:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9080</guid>
		<description>It runs ok over here. How did you copy the script Jon?</description>
		<content:encoded><![CDATA[<p>It runs ok over here. How did you copy the script Jon?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9077</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 25 Nov 2008 15:05:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9077</guid>
		<description>I&#039;m getting an error when I run this:

Line 150
Char: 41
Error: Expected &#039;Then&#039;

Any ideas?</description>
		<content:encoded><![CDATA[<p>I&#8217;m getting an error when I run this:</p>
<p>Line 150<br />
Char: 41<br />
Error: Expected &#8216;Then&#8217;</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-9001</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Sat, 15 Nov 2008 19:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-9001</guid>
		<description>I run almost the exact same script at the beginning of each month to clear al my server logs and archive them centrally.

I also run a daily script from Redmond Magazine (http://redmondmag.com/columns/article.asp?EditorialsID=1653) that emails me a log of all the error and warning events on all my servers for the past 24 hours.  You need to customize it to get rid of the noise, but it works well.  It has alerted me to problems before they became critical and allowed me to resolve them without downtime.</description>
		<content:encoded><![CDATA[<p>I run almost the exact same script at the beginning of each month to clear al my server logs and archive them centrally.</p>
<p>I also run a daily script from Redmond Magazine (<a href="http://redmondmag.com/columns/article.asp?EditorialsID=1653" rel="nofollow">http://redmondmag.com/columns/article.asp?EditorialsID=1653</a>) that emails me a log of all the error and warning events on all my servers for the past 24 hours.  You need to customize it to get rid of the noise, but it works well.  It has alerted me to problems before they became critical and allowed me to resolve them without downtime.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy L. Gaddis</title>
		<link>http://www.asktheadmin.com/2009/06/guerrilla-event-log-archiving-why-and-how.html/comment-page-1#comment-8996</link>
		<dc:creator>Jeremy L. Gaddis</dc:creator>
		<pubDate>Sat, 15 Nov 2008 02:32:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1975#comment-8996</guid>
		<description>Install Splunk on one of your Linux boxes, and Snare on your Windows PCs.</description>
		<content:encoded><![CDATA[<p>Install Splunk on one of your Linux boxes, and Snare on your Windows PCs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.asktheadmin.com @ 2012-02-09 20:58:39 -->
