<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'EVT input format'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=EVT+input+format&amp;orTags=0</link><description>Search results matching tag 'EVT input format'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Prining</title><link>http://forums.iis.net/p/1162008/1921810.aspx#1921810</link><pubDate>Thu, 22 Oct 2009 21:50:45 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1921810</guid><dc:creator>hg363</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;p&gt;Hi to all forum members.&lt;/p&gt;
&lt;p&gt;Is there an SQL script in existance or can one be configured that when executed with Log Parser would show which printers a client printed to from a MS Windows XP Pro PC?&lt;/p&gt;
&lt;p&gt;And if this&amp;nbsp;is possible can the script then be inflated to show&amp;nbsp;what dates&amp;nbsp;the print jobs were sent to the printers and if possible the print job name and how many pages?&lt;/p&gt;
&lt;p&gt;If some one could kindly show me how this can be done, it would be most helpful, regards HG363 UK London &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Event logs Parsing issue</title><link>http://forums.iis.net/p/1161552/1919792.aspx#1919792</link><pubDate>Wed, 07 Oct 2009 13:03:44 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1919792</guid><dc:creator>mritorto</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;Guys,&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here is my issue I have a batch job that runs log parser to collect the event logs from my servers and dumps the info into an excel spreadsheet.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Some times it works perfectly and some times it does not.&amp;nbsp; The record titles like computername or timegenerated some times show up in the spreadsheet and other times it does not not.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Any idea why. I do have other batch files that run thru out the day looking the servers for specfic event log error messages like account lockouts but the one listed below only runs once per day.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I even run it from a different machine and I get the same results&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Any help would be appreciated. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;for /f %%i in (servers.txt) do logparser &amp;quot;select&amp;nbsp; distinct timegenerated,EventID,EventTypeName,Strings,ComputerName,Message into eventlogs.csv from \\%%i\application where&amp;nbsp; eventtypename like &amp;#39;error event&amp;#39; and timegenerated &amp;gt;= to_localtime (sub(system_timestamp(), timestamp (&amp;#39;23&amp;#39;,&amp;#39;hh&amp;#39;) ) ) order by timegenerated &amp;quot; -i:evt -o:csv -filemode:0&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Logparser 2.2</title><link>http://forums.iis.net/p/1157198/1901996.aspx#1901996</link><pubDate>Mon, 27 Apr 2009 15:12:52 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1901996</guid><dc:creator>rlawson</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;p&gt;If logparser 2.2 compatible with windows 2008/64bit? to see security .evt logs&lt;/p&gt;
&lt;p&gt;I I am using logparser 2.2 and it was working perfect until the domain controllers were upgraded to windows 2008 64bit, now I get a file is corrupt.&lt;/p&gt;
&lt;p&gt;Need help&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>EVT Log Corrupted or Being Used By Another Process</title><link>http://forums.iis.net/p/1150109/1872699.aspx#1872699</link><pubDate>Thu, 26 Jun 2008 18:35:59 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1872699</guid><dc:creator>hullflyer</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;p&gt;Relatively new to log parser (v 2.2).&amp;nbsp; Have ASP pages running fine to query IIS web logs.&amp;nbsp; Now trying to get one to report on Event logs, but can&amp;#39;t figure out how to get around access errors.&amp;nbsp; When I set the path to the actual event log file, I get:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CLogQueryClass&lt;font face="Times New Roman" size="3"&gt; &lt;/font&gt;&lt;font face="Arial" size="2"&gt;error &amp;#39;80070020&amp;#39;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt; &lt;font face="Arial" size="2"&gt;[The process cannot access the file because it is being used by another process.]&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The script that results in that error (vbscript in asp page):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;pathVar = &amp;quot;c:\WINDOWS\system32\config\SysEvent.evt&amp;quot;&lt;br /&gt;fileQry = &amp;quot;SELECT * FROM &amp;quot;&amp;amp;pathVar&lt;br /&gt;set logQuery = server.createobject(&amp;quot;MSUtil.LogQuery&amp;quot;)&lt;br /&gt;set EVT = Server.CreateObject(&amp;quot;MSUtil.LogQuery.EventLogInputFormat&amp;quot;)&lt;br /&gt;set recordSet = logQuery.Execute(fileQry,EVT)&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I made sure the pathVar is right and I set permissions on that folder to allow everyone full control, and it still gives the same error.&amp;nbsp; So, thinking that it&amp;#39;s a file sharing violation, I set up a script to copy that file to a new one in the same folder.&amp;nbsp; Now that gives a new error:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CLogQueryClass&lt;font face="Times New Roman" size="3"&gt; &lt;/font&gt;&lt;font face="Arial" size="2"&gt;error &amp;#39;800705dc&amp;#39;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt; &lt;font face="Arial" size="2"&gt;[The event log file is corrupted.]&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;font face="Arial" size="2"&gt;The script that &amp;nbsp;results in this new error is:&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;pathVar = &amp;quot;c:\WINDOWS\system32\config\SysEvent.evt&amp;quot;&lt;br /&gt;dim fso&lt;br /&gt;set fso = server.createobject(&amp;quot;Scripting.FileSystemObject&amp;quot;)&lt;br /&gt;dim txtPath&lt;br /&gt;txtPath = &amp;quot;C:\WINDOWS\system32\config\MyEvent2.evt&amp;quot;&lt;br /&gt;fso.CopyFile pathVar,txtPath&lt;br /&gt;fileQry = &amp;quot;SELECT * FROM &amp;#39;&amp;quot;&amp;amp;txtPath&amp;amp;&amp;quot;&amp;#39; &amp;#39;&amp;quot;&lt;br /&gt;&amp;nbsp;set logQuery = server.createobject(&amp;quot;MSUtil.LogQuery&amp;quot;)&lt;br /&gt;&amp;nbsp;set EVT = Server.CreateObject(&amp;quot;MSUtil.LogQuery.EventLogInputFormat&amp;quot;)&lt;br /&gt;set recordSet = logQuery.Execute(fileQry,EVT)&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;font face="Arial" size="2"&gt;I double checked and I can open that original event log in the WMI Event Viewer just fine, so the original file being copied appears to be good.&amp;nbsp; The new file MyEvent2.evt is there and the same size as the original.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;Both errors are the same regardless of which event log file I specify.&lt;/p&gt;
&lt;p&gt;There is surprisingly little in the book or on the web about webifying log parser, especially in vbscript.&amp;nbsp; Any ideas what I&amp;#39;m doing wrong?&amp;nbsp; Is there a different input format I s/b using for asp?&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>WinXP (no Eng, eg DE-DE  ) localized event logs</title><link>http://forums.iis.net/p/1148576/1866091.aspx#1866091</link><pubDate>Tue, 25 Mar 2008 20:59:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1866091</guid><dc:creator>Milano</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;p&gt;Does logparser support localized event logs? If so, is there anything special needs to be done to get this going?&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>RE: Querying for a date</title><link>http://forums.iis.net/p/1146017/1855271.aspx#1855271</link><pubDate>Mon, 18 Jun 2007 11:14:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1855271</guid><dc:creator>LogParser User : dssbob</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;Ok...say my normal operating hours are 9am-5pm.&lt;/P&gt;&lt;P&gt;How would I write a query to look for logons outside of that time period?&lt;/P&gt;&lt;P&gt;I know how to&amp;nbsp;look within that timeframe, but cant figure out how to look outside of that timeframe.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description></item><item><title>RE: Querying for a date</title><link>http://forums.iis.net/p/1146017/1855263.aspx#1855263</link><pubDate>Fri, 15 Jun 2007 16:47:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1855263</guid><dc:creator>LogParser User : dssbob</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;I switched to the new version and its working great...Thanks!&lt;/P&gt;</description></item><item><title>RE: Querying for a date</title><link>http://forums.iis.net/p/1146017/1855278.aspx#1855278</link><pubDate>Thu, 14 Jun 2007 22:24:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1855278</guid><dc:creator>LogParser User : José Gisbert</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;I probe (copy &amp;amp; paste) your&amp;nbsp;post&amp;nbsp;and works fine&amp;nbsp;with Logparser v2.2.10 , which version have you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>RE: Querying for a date</title><link>http://forums.iis.net/p/1146017/1855267.aspx#1855267</link><pubDate>Thu, 14 Jun 2007 10:48:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1855267</guid><dc:creator>LogParser User : dssbob</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;I have tried that:&lt;/P&gt;&lt;P&gt;LogParser.exe "select EventID, TimeGenerated, Message, ComputerName, RESOLVE_SID(SID) as Username from C:\Log_Files\2007_6_13\evt\SecEvent_20070613_07.Evt TO TEST.html WHERE TimeGenerated BETWEEN TO_TIMESTAMP('2007-06-08 00:00:01', 'yyyy-MM-dd hh:mm:ss') AND TO_TIMESTAMP('2007-06-08 23:59:59', 'yyyy-MM-dd hh:mm:ss')" -i:EVT -o:TPL -tpl:LogParserTemplate.txt&lt;BR&gt;&lt;/P&gt;&lt;P&gt;and keep getting this error :&lt;/P&gt;&lt;P&gt;Syntax error: &amp;lt;tern2&amp;gt;: 'BETWEEN' is not a vailid operator&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>Parse by username</title><link>http://forums.iis.net/p/1146039/1851251.aspx#1851251</link><pubDate>Thu, 07 Jun 2007 18:26:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1851251</guid><dc:creator>LogParser User : dssbob</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;Is there anyway to just grab all events in the Security log that are generated by a specific user?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description></item></channel></rss>