event IDs

Discuss Windows Event Log events. What they mean, what they tell you about your machine's security ... and whatever questions else you have.

Moderator: alorbach

event IDs

Postby skosterow on Fri Jul 23, 2004 7:19 am

Does any one have a list of all windows event ID and there meanings PLEASE HELP!

Ill send you a copy of the usable pregram im writting (wich i wont be charging for)

- scott skosterow@skosterow.net
skosterow
 

Postby alorbach on Fri Jul 23, 2004 9:56 am

We have a list of many events online in our Event Reference:
http://www.monitorware.com/en/events/
User avatar
alorbach
Site Admin
 
Posts: 819
Joined: Thu Feb 13, 2003 11:55 am

Thanks - Alorbach

Postby skosterow on Fri Jul 23, 2004 8:34 pm

Thanks for writting would it be possible to get a dump from you on the events?

im trying to write a script in perl that will parse out the events that are important and then lable them with the meaning - Its for my own business and it would be used as a tool, to help me help my customers. I'd be more then willing to share it after its complete, i have the log parser and the viewer almost completed. Not to mention that I will also post it on hotscripts.com for free.
skosterow
 

Postby rgerhards on Fri Jul 23, 2004 10:01 pm

I am sorry, but this database is not publically available. I suggest, however, that you ask Microsoft - I think you will get an answer.

Best regards,
Rainer Gerhards
Adiscon
User avatar
rgerhards
Site Admin
 
Posts: 1162
Joined: Thu Feb 13, 2003 11:57 am

Thanks

Postby Skosterow on Sat Jul 24, 2004 3:59 am

May I ask why its not publicly available?
Skosterow
 

Thanks for nothing

Postby skosterow on Thu Jul 29, 2004 11:33 pm

BTW your database is Incorrect - as well as it does NOT have all the codes - But thanks for replying - to my last post - Ummmmm hiding something? Or hoping that this will be your cash cow?

Any how have a great day ;-)

- Scott
skosterow
 

Postby rgerhards on Fri Jul 30, 2004 8:33 am

Hi Scott,

sorry for not replying to your last post. But, honestly, I do not think we need to offer everything we have for free. If you know Adiscon - and myself - a little, you probably know that we offer lots of free ressources and are very share-minded in our business. However, there is a simple fact that a business needs funding. Without funding not only the event database will disappear but also other valuable ressources. Its nice to have everything for free. The bad thing, however, is that our folks don't like to work for free ;)

In regard to the database: we never claimed it is 100% accurate. And if you read Andre's post, he said it has "many events". It does not have all events. Its not guaranteed to have. If you have read the description on the database pages, you've eventually noted that we say we offer it is a free ressource to aid in parsing. Nothing else. Also we do not expect to make it a cash-cow. Even when: would it be bad to fund it somehow?

I think we provided good suggestions, including talking to Microsoft. I think it would now be your turn to invest some of your own time to finish your task. It doesn't help if you expect the rest of the world to support you. Wouldn't it look a bit unnatural if we support a potential competitor? Really, no kidding: I think it is fair that we try to fund ourselfs from the work we do. Maybe you now begin to realize why we need to charge for *some* things - you see this by finding that some things are simply time consuming. On the other hand, we even offer a free library for enhanced syslog integration, so I personally do not like to be told that we are the cash-grabbing bad guys. But, of course, it's up to you what you think ;)

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1162
Joined: Thu Feb 13, 2003 11:57 am

Postby skosterow on Fri Jul 30, 2004 4:43 pm

rgerhards -

Thanks for posting the note -

I understand completly RE the not wanting to work for free - however, I offered you somehting in return for something, wasn't like I was trying to ask for something for FREE FREE. I offered to give you the parser that I am writting - to use as YOU saw fit, not to mention that if you said okay ww'll dump you the DB with the clause that you don't give it away. I could live with that. Not to mention that the parser that im wortting could very well help you - in the sense that the way im writting it it could pick up NEW events that arnt already in your DB.

This might help you as a company be able to expand on lets say - upload a dumped Event File and we will parse it for you!!!! I wont be doing that at all, this is completly for internal use with my own customers. I guess what I'm trying to say is that we would BOTH benifit. But what do I know.

As far as the suggestions - Buddy, I have invested time in this - and to suggest that I havent, to make yourself look good - is pretty snotty. I have called Microsoft - I have scowered the web, I have made postings on other sites as well as yours, all this to no avail. So, in the end we will come up with our own DB.

Again to rebutt, your comments at the end, sir 1st I am NOT your competitor, I would not nor do I wish to do what you guys do - I dont ever forsee having a completly admistrative web site that displays event ID's. Again, the use of the DB would have been to expand on YOUR use of the Event ID's. Then possibly help your company offer up something that I DONT SEE IN THE MARKET PLACE. On YOUR website NOT mine! Maybe if you didnt look a gift horse in the mouth, or be so defensive in the protection of data, that in NO WAY is sensitive, you would have been able to see the POTENTIAL in supporting yourself, with value added services.

Thanks though -

Scott skosterow@skosterow.net
skosterow
 

Google Ads



Return to Windows Events

Who is online

Users browsing this forum: No registered users and 0 guests

cron