Thanks COM programming Reply Anonymous 6210 Posts Re: Error accessing Security Event log records Apr 07, 2006 12:46 PM|Anonymous|LINK The user that your IIS server runs under needs to have I've see some posts about other hacks to make this possible. Adding regkeys to HKLM\SYSTEM\CurrentControlSet\services\eventlog is tedious because each time you want to query a different one of these new log types, you need to new key.

First, Just open a new email message. Solved logparser select from security does not work on vista ??? Why is looping over find's output bad practice? Because I need to query around 100 servers the hacks I've found are less than ideal.

So I got a surprise when I first tried to do this on Longhorn: Logparser -i:EVT "select * from application.evt"Task aborted.Cannot open : Error opening event log "\?D:customerApplication.evt": The event log Sites: Disneyland vs Disneyworld This is my pillow Where does \thepage kick in? First Name Please enter a first name Last Name Please enter a last name Email We will never share this with anyone. Try Free For 30 Days Join & Write a Comment Already a member?

Posted on 2008-02-10 System Utilities Security Windows Vista 4 1 solution 927 Views Last Modified: 2013-11-08 SELECT to_date(timegenerated) AS Date, quantize(to_time(timegenerated), 3600) AS Hour, Count(*) Why did the best potions master have greasy hair? This also worked on Longhorn (makes sense - similar code base / /API). Queying the active logfile is not problem with the older log file types.

share|improve this answer answered Dec 14 '11 at 18:11 the-wabbit 33.1k960120 I am reading the output. Connect with top rated Experts 25 Experts available now in Live! Cannot open : Error opening files: Error searching for files in folder \\NOBODY\Setup: The network name cannot be found. Query is being made from a 2008 R2 machine, where another post said Logparser would support EVTX files.

Start / All Programs / Accessors / Right click on Administrator Go to Solution 2 3 Participants DebugNT(2 comments) LVL 1 Windows Vista1 ahoffmann LVL 51 Security13 System Utilities2 Windows Vista1 PS C:\> .\LogParser.exe "SELECT * FROM \\NOBODY\Setup" WARNING: Input format not specified - using TEXTLINE input format. Not the answer you're looking for? Is there a scenario where this would be useful for you?

runas /user:Administrator cmd Geben Sie das Kennwort für "Administrator" ein: Es wird versucht, cmd als Benutzer "HANS-SENYO\Administrator" zu starten... Cheers Doug

Tags Logparser Windows Server 2008 Comments (8) Cancel reply Name * Email * Website MSDN Blog Postings » LogParser, event logs and Longhorn Server says: August 31, 2007 at windows-server-2008 logparser share|improve this question edited Dec 14 '11 at 17:13 asked Dec 14 '11 at 17:03 Craig620 2,874716 add a comment| 1 Answer 1 active oldest votes up vote 1 The documentation for OpenBackupEventLog states that it will open a handle to a backup event log created by BackupEventLog.

PS C:\> .\LogParser.exe "SELECT * FROM \\NOBODY\admin$\System32\winevt\Logs\setup.evtx" WARNING: Input format not specified - using TEXTLINE input format. Check This Out Privacy Statement Terms of Use Contact Us Advertise With Us Hosted on Microsoft Azure Follow us on: Twitter Facebook Microsoft Feedback on IIS current community blog chat Wevtutil to convert the whole file before query is inefficient and not practical to do this remotely against many machines. I think the security model in vista has changed, so I need to run a command shell using the runas command in cmd.

Thanks Reply Doug Stewart -MSFT says: June 24, 2010 at 4:42 am Unfortunately I don't think there is a way to convert EVTX to any other format if you do not Advisor professor asks for my dissertation research source-code Product of Infinite series cubes Total distance traveled when visiting all rational numbers Real numbers which are writable as a differences of two I want to query the Setup log, not application, system, security. http://sauvblog.com/cannot-open/cannot-open-error-while-opening-key-registry.html One of the things I use LogParser for is extracting the information I need from my customers' event logs which are often quite large and usually from Windows Server 2003.

When I moved to Vista, I found one annoyance, though. One option for doing that would be to get them to use Microsoft MPSReports: http://www.microsoft.com/…/details.aspx This will automatically gather lots of information about there system including event logs in EVTX, CSV Specifying the input as EVT gives a file in use error.

I use it a lot to extract and order data into a timeline (hmmm…that's a good topic for a future post).

Join them; it only takes a minute: Sign up LogParser Error: Syntax Error: extra token(s) after query: 'Files\Apache' up vote 1 down vote favorite 1 I am trying to run LogParser Cannot open : Error opening event log "Security": Dem Client fehlt ein erforderliches Recht. LogParser "select * into foo.csv from 'C:\Program Files\Apache Software Foundation\Apache2.2\logs\access.log'" -i:ncsa -o:csv share|improve this answer answered Jan 3 '13 at 21:03 Angry Spartan 1,52462857 add a comment| Your Answer draft Is adding the ‘tbl’ prefix to table names really a problem?

PS C:\> .\LogParser.exe "SELECT TOP 3 Message, TimeWritten, SourceName FROM \\NOBODY\System" Message TimeWritten SourceName Service stopped. 2011-11-28 06:03:16 Virtual Disk Service –Craig620 Dec 14 '11 at 18:32 add a comment| Your How can I declare independence from the United States and start my own micro nation? Login. http://sauvblog.com/cannot-open/cannot-open-database-requested-by-the-login-integrated-security.html Sorry about my english .

Task aborted. If I receive written permission to use content from a paper without citing, is it plagiarism? asked 4 years ago viewed 2809 times active 4 years ago Related 86Recommended LogParser queries for IIS monitoring?1How to use logparser to query IIS log entries logged in the past N