{"id":237,"date":"2016-05-19T23:36:37","date_gmt":"2016-05-19T23:36:37","guid":{"rendered":"http:\/\/eventlogxp.com\/blog\/?p=237"},"modified":"2016-05-20T11:39:03","modified_gmt":"2016-05-20T11:39:03","slug":"automating-event-log-backup","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/automating-event-log-backup\/","title":{"rendered":"Automating event log backup"},"content":{"rendered":"<p>Recently we received a question from our customer who asked about regular backing up of system and application event logs. He wanted to backup only local logs, but let&#8217;s extend the task for remote logs as well. So our task is to backup System and Application event logs from a local computer and remote machine (SERV1) into a folder two times a week.<\/p>\n<p>Let&#8217;s try to do it using standard tools.\u00a0Windows event viewer lets you backup event log \u2013 there is a command in Event Viewer \u2013 &#8220;Save all event as&#8221; and you should save them into evtx format. However, it doesn&#8217;t allow you to backup an event log from a remote server to a local computer or visa-versa. \u00a0You will get a message:<\/p>\n<blockquote><p>An error occurred while Event Viewer was saving a log file in .evtx format from SERVER to PATH.<br \/>\nEvents from the remote computer cannot be saved into .evtx format files on the local computer. If you want to save the events to the local computer, select a different file format. To save the events in .evtx format, save them onto the remote computer.<\/p><\/blockquote>\n<p>Why this happens? Windows Event Log Service (eventlog), which is responsible for all main event log functionality is running under LocalService account. LocalService presents anonymous credentials on the network, so it has no permissions to backup event log anywhere, but computer on which the service is running. The same limitation has wevtutil.exe command. It works with local event logs only.<\/p>\n<p>What about Event Log Explorer? We designed Event Log Explorer to backup remote event logs as easy as local ones. When backing up a remote logs, it saves the log into a shared folder on a remove computer and then moves it into the target folder.<\/p>\n<p>Just click right mouse button a log you wish to backup in the tree and select <em>Save log as<\/em>. Event Log Explorer will do the rest.<\/p>\n<p><a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/elex-backup.png\" rel=\"attachment wp-att-238\" data-rel=\"lightbox-gallery-2cXc9SWr\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-238\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/elex-backup-300x139.png\" alt=\"event log explorer backup\" width=\"300\" height=\"139\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/elex-backup-300x139.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/elex-backup.png 437w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Note that you must have administrative permissions on the server Serv1 or you won&#8217;t be able to access files from ADMIN$ resource.<\/p>\n<p>Of course, you can backup event logs manually, but our user asked us to automate process. Event Log Explorer comes with ELBACK utility which can be located in the application folder (default location is &#8220;C:\\Program Files (x86)\\Event Log Explorer\\elback.exe&#8221;). This utility developed exactly for batch backup of event logs. Detailed information about this utility available in Event Log Explorer <a href=\"http:\/\/eventlogxp.com\/help\/elback.html\" target=\"_blank\">help<\/a>.<\/p>\n<p>Here is our command line to backup Application and System logs from a local PC and Serv1:<\/p>\n<pre>elback.exe D:\\backup Application System \\\\Serv1\\Application \\\\Serv1\\System \/clear<\/pre>\n<p>Remove <em>\/clear<\/em> option if you don&#8217;t want to empty log automatically after backup.<\/p>\n<p>Run this command to test it. If it works correctly, you will see 4 new files in D:\\Backup folder that looks like Serv1-System-2016-05-18-10-56-056.evt.<\/p>\n<p>Now we can automate the process. I will use Windows Scheduler. In article <a href=\"http:\/\/eventlogxp.com\/blog\/exporting-event-logs-with-windows-powershell\/\">Exporting event logs with Windows PowerShell<\/a> I described how to create Windows Scheduler task with PowerShell. Here I will just use Windows UI for this.<\/p>\n<blockquote><p>Click Windows Start button, then All Programs-&gt;Accessories-&gt;System Tools-&gt;Task Scheduler<br \/>\nSelect Task Scheduler Library in the tree.<br \/>\nCreate Basic Task from the menu.<br \/>\nGive any name to the task, e.g. &#8220;Logs backup&#8221;.<br \/>\nClick Next.<br \/>\nOn Task Trigger page select Weekly.<br \/>\nClick Next.<br \/>\nSpecify when you want to run the task.<br \/>\nClick Next.<br \/>\nSelect &#8220;Start a program&#8221;<br \/>\nclick Next.<br \/>\nIn Program\/Script line type<br \/>\n<em>&#8220;C:\\Program Files (x86)\\Event Log Explorer\\elback.exe&#8221;<\/em><br \/>\nIn Add arguments type<br \/>\n<em>D:\\backup Application System \\\\Serv1\\Application \\\\Serv1\\System \/clear<br \/>\n<\/em>Click Next<br \/>\nClick Finish.<\/p><\/blockquote>\n<p>Now you can find your task in the list.<br \/>\nClick right mouse button on the task and select Run to test it.<br \/>\nCheck &#8220;D:\\Backup&#8221; folder if new evtx files appear.<\/p>\n<p>Important note: if you decide to backup a local Security event log, you will probably need to elevate permissions to access the security log. To do so, click right mouse button on Logs backup task in Windows Scheduler and select Properties. In the Properties dialog enable checkbox &#8220;Run with highest privileges&#8221;.<\/p>\n<p><a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/task-scheduler.png\" rel=\"attachment wp-att-239\" data-rel=\"lightbox-gallery-2cXc9SWr\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-239\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/task-scheduler-300x226.png\" alt=\"Scheduling event log backup\" width=\"300\" height=\"226\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/task-scheduler-300x226.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/05\/task-scheduler.png 646w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Don&#8217;t forget to the task before going production.<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;t=Automating%20event%20log%20backup&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F05%2Fevent-log-backup-schedule.png&#038;p&#091;title&#093;=Automating%20event%20log%20backup\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;title=Automating%20event%20log%20backup\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F05%2Fevent-log-backup-schedule.png&#038;description=Automating%20event%20log%20backup\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237&#038;title=Automating%20event%20log%20backup\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Automating%20event%20log%20backup&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F237\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Recently we received a question from our customer who asked about regular backing up of system and application event logs. He wanted to backup only local logs, but let&#8217;s extend the task for remote logs as well. So our task is to backup System and Application event logs from a local computer and remote machine (SERV1) into a folder two times a week. Let&#8217;s try\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/automating-event-log-backup\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":240,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[7],"tags":[58,53],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/237"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=237"}],"version-history":[{"count":4,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/237\/revisions"}],"predecessor-version":[{"id":244,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/237\/revisions\/244"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/240"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}