﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / IT Audit / Windows Server  / How to easily obtain Event Log activity metrics / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 11:52:51 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: How to easily obtain Event Log activity metrics</title><link>http://forum.ultimatewindowssecurity.com/Topic84-9-1.aspx</link><description>I would suggest logparser; you will need to use the count(*) function and the group by clause. &lt;/P&gt;&lt;P&gt;The command will be something close to &lt;/P&gt;&lt;P&gt;logparser "select TimeGenerated, count(*) from security group by TimeGenerated" &lt;/P&gt;&lt;P&gt;But you will need to use the substring function on TimeGenerated to chop off the time and leave just the date. You can download logparser at http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en and there are examples of its use all over the Internet.</description><pubDate>Sat, 02 May 2009 18:50:46 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>How to easily obtain Event Log activity metrics</title><link>http://forum.ultimatewindowssecurity.com/Topic84-9-1.aspx</link><description>How much log data and/or how many events is a given server creating in a typical day?  In a typical week?  At its peak moment (Monday morning)?&lt;br&gt;&lt;br&gt;This question is of particular interest for Domain Controllers, and I don't know the answer.  Are there any built-in Windows tools or interfaces for displaying this type of data?  Or any simple (and free) third party tools for doing so?</description><pubDate>Fri, 01 May 2009 17:17:48 GMT</pubDate><dc:creator>ottermaton</dc:creator></item></channel></rss>
