{"id":123,"date":"2016-03-21T03:28:54","date_gmt":"2016-03-21T03:28:54","guid":{"rendered":"http:\/\/eventlogxp.com\/blog\/?p=123"},"modified":"2016-03-30T02:08:12","modified_gmt":"2016-03-30T02:08:12","slug":"case-study-generating-regular-reports-about-the-problems-in-your-windows-network","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/case-study-generating-regular-reports-about-the-problems-in-your-windows-network\/","title":{"rendered":"Case study \u2013 generating regular reports about the problems in your Windows network"},"content":{"rendered":"<p>Recently one of our clients asked us about the best way to organize a passive monitoring of their servers. The client told us that they don&#8217;t need to monitor the servers actively, but they want to have weekly reports about the problems. They tried to gather events using Windows PowerShell and export them to CSV format (to view events in Excel), but finally they gave up.<\/p>\n<h3>Task<\/h3>\n<p>The customer reported that he is a system administrator of a network with 4 Windows 2008 Severs and he needs to check out only system and application event logs of these servers. Ideally, these machines should generate only information events (no error or warnings). He would like to have reports of the problems in the beginning of every week.<\/p>\n<p>So we can reformulate the task as follows:<\/p>\n<p><strong><em>Generate weekly report of all non-Information events in Application and System logs.<\/em><\/strong><\/p>\n<h3><strong>Our solution<\/strong><\/h3>\n<p>First of all, we suggest to start a new copy of Event Log Explorer and create a new workspace for this task (use File-&gt;New workspace command). You can ignore this suggestion, but we recommend to always separate long-running tasks (like active monitoring or scheduled tasks) from operative event log tasks.<\/p>\n<p>Then we need to add the required servers to the tree. This can be done either with help of Add Computer Wizards or manually (by pressing Add computer button).<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/servers-added.jpg\" rel=\"attachment wp-att-124\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-124\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/servers-added.jpg\" alt=\"Servers added\" width=\"222\" height=\"192\" \/><\/a><\/p>\n<p>It&#8217;s time to create our log view. We will consolidate all the application and system logs from these servers in one view.<\/p>\n<p>Open Serv1 server in the tree and double click on System log to open in.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened.jpg\" rel=\"attachment wp-att-125\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-125\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened-300x189.jpg\" alt=\"Open system event log on server SRV1\" width=\"300\" height=\"189\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened-300x189.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened-768x483.jpg 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened-660x415.jpg 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/system-log-on-srv1-opened.jpg 835w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>We can subsequently add other event logs to the view, but it is better to set on-load filter first.\u00a0 Go to View-&gt;Log Loading Options, select Load event from last 7 days (we need a report for the last week) and untick Information type.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/log-loading-filter-lastweek-noinfo.jpg\" rel=\"attachment wp-att-126\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-126\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/log-loading-filter-lastweek-noinfo-300x135.jpg\" alt=\"log loading filter - (no information, last week)\" width=\"300\" height=\"135\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/log-loading-filter-lastweek-noinfo-300x135.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/log-loading-filter-lastweek-noinfo.jpg 366w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Now we can add other logs to the view and they will be filtered automatically:<\/p>\n<p>Right click on Application log of Serv1 and select Merge with the current view. Open Serv2, Serv3 and Serv4 and continue to add their application and system logs to the view.<\/p>\n<p>Click on Date column to sort all merged events by date and time.<\/p>\n<p>Rename unclear &#8220;Merger&#8221; name to something better: select View-&gt;Rename and change the name to &#8220;<em>Weekly report<\/em>&#8220;.<\/p>\n<p>Now you should get something like this:<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export.jpg\" rel=\"attachment wp-att-127\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-127\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export-300x189.jpg\" alt=\"consolidated event logs\" width=\"300\" height=\"189\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export-300x189.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export-768x483.jpg 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export-660x415.jpg 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/consolidated-eventlog-for-export.jpg 835w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><strong>Let&#8217;s automate this.<\/strong><\/p>\n<p>Select Advanced-&gt;Scheduler from the main menu and create a new task. Name the task as &#8220;<em>Problem Report<\/em>&#8221; and click Next.<\/p>\n<p>Set when we want to run the task, e.g. on Mondays at 7:00:<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/sched-trigger.jpg\" rel=\"attachment wp-att-128\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-128\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/sched-trigger-300x217.jpg\" alt=\"Event log scheduler\" width=\"300\" height=\"217\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/sched-trigger-300x217.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/sched-trigger.jpg 414w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Click Next and select what we want to do: Refresh, then export:<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/task-export-events-excel.jpg\" rel=\"attachment wp-att-129\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-129\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/task-export-events-excel-300x217.jpg\" alt=\"event log - export to excel\" width=\"300\" height=\"217\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/task-export-events-excel-300x217.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/task-export-events-excel.jpg 414w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>We will export to Excel 2007 format with event descriptions.<\/p>\n<p>Leave &#8220;Export path&#8221; with the default value &#8220;<em>%USERPROFILE%\\Documents&#8221;<\/em> which means that Event Log Explorer will save reports in Documents folder of your user profile (note that in Export path you can enter any Windows path, including UNC paths, so it lets you store reports on remote computers).<\/p>\n<p>Click Next, then Finish and then OK in Scheduler window. \u00a0Now you can save the workspace (File-&gt;Save workspace) and minimize the application (you can minimize it even into the notification area).<\/p>\n<p>That&#8217;s all. On Monday at 7:00 AM, Event Log Explorer will load error and warning events for the last week from the servers and export these events into XSLX file:<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel.jpg\" rel=\"attachment wp-att-130\" data-rel=\"lightbox-gallery-cft6hzzi\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-130\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel-300x98.jpg\" alt=\"exported to excel eventlog\" width=\"300\" height=\"98\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel-300x98.jpg 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel-768x250.jpg 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel-660x215.jpg 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/03\/eventlog-exported-excel.jpg 800w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>And even if you close the program or restart your PC, you can always run Event Log Explorer and open your workspace \u2013 this will load all your settings and restore the scheduler.<\/p>\n<h3>Conclusion<\/h3>\n<p>As you can see, tuning Event Log Explorer didn&#8217;t take a lot of time (I did it in just 4 minutes), and what is more important you will have regular reports about problems from different sources without extra work! Needless to say that you can easily modify event filters to fulfill your specific requirements.<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;t=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F03%2Fgenerating-event-log-reports.jpg&#038;p&#091;title&#093;=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;title=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F03%2Fgenerating-event-log-reports.jpg&#038;description=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123&#038;title=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Case%20study%20%E2%80%93%20generating%20regular%20reports%20about%20the%20problems%20in%20your%20Windows%20network&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F123\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Recently one of our clients asked us about the best way to organize a passive monitoring of their servers. The client told us that they don&#8217;t need to monitor the servers actively, but they want to have weekly reports about the problems. They tried to gather events using Windows PowerShell and export them to CSV format (to view events in Excel), but finally they gave\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/case-study-generating-regular-reports-about-the-problems-in-your-windows-network\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":132,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[7,39],"tags":[38,54,56,53,50,9],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/123"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=123"}],"version-history":[{"count":1,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/123\/revisions"}],"predecessor-version":[{"id":131,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/123\/revisions\/131"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/132"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}