This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. Centralizing Event Logs on Windows 2000 This case study will detail how I setup a central repository for server logs and daily notifications of events that might indicate a security incident. This was done on a limited budget using free tools available from the internet and software already in use for other projects. My goal was to consolidate the Eventviewer logs, Internet Information Services (IIS) logs, and Urlscan logs from 15 Windows 2000 web servers into a database I could query against. I would then have the results of the queries automatically emaile... Copyright SANS Institut