Jump to content
Microsoft Windows Bulletin Board

Domain Controllers Security Logs Archival and Collection


Recommended Posts

Guest Shahid Roofi
Posted

We want to centralize all security logs from all 8 DCs. These logs grow rapidly so need to change the location to D or E drive and then set Auto Archive settings. (otherwise C Drive will be filled up in hours)

 

Next challenge is to collect all of these and compress them and put them in one machine.

 

Option1: use scripts that copy all the archive files created on DCs and paste them on file share and deleting the originals.

 

Option2: use event collection/subscription feature.

 

The failure of any of the approach will cause the D drive on the DC to get filled up easily and then DC will be in abnormal state.

 

What is the common solution around this? (apart from 3rd party products).

 

Ideally we need all security events from all DCs

 

 

Shahid Roofi

 

Continue reading...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...