NetWrix Event Log Manager
|
Will automatically archive and consolidate audit event logs. Event log data is unique source of information for security, audit, compliance, troubleshooting. Native event logging mechanisms provided by Windows systems don't have built-in consolidation, archiving and reporting features, required to impactfully utilize event data and comply with external regulations like SOX, HIPAA, PCI, and others. Numerous event logs in uncompressed format spread all over the network, with tons of events lost every day because of overwrites, represent a big security and compliance issue.
NetWrix Event Log Manager is a free event log consolidation, alerting and archiving tool, that allows you to collect events logs from multiple computers across the network, alert on most critical events, and centrally store all events in a compressed format, enabling handy analysis archived event log data.
Features and benefits:
1. Event Log Archiving
2. Event Log Consolidation
3. Real-Time Alerting
4. Web-based Reporting
The following predefined reports are available in the commercial version of the product. You can easily create your custom reports or order them from NetWrix Professional Services. Up to 3 custom reports can be provided at no charge with every purchase.
1. Account Management Shows account management operations: creation and deletion of accounts and groups and group membership.
2. Administrative Password Resets Shows all admin-initiated password resets.
3. All Events by Computer Shows all events grouped by computer, filtered by date range and other parameters.
4. All Events by Date Shows all events grouped by date, filtered by date range and other parameters.
5. All Events by Source Shows all events grouped by source (e.g. 'Security', 'Application Management'), filtered by date range and other parameters.
6. All Events by User Shows all events grouped by user, filtered by date range and other parameters.
7. All Object Access Events by User Shows all object access events, e.g. file and folder access, registry, and other system objects. Object access auditing must be enabled for this report to work.
8. All System Events Shows events generated by system processes, including startup and shutdown, system time, system failures, and other critical events.
9. Audit Log Cleared Shows audit trail cleanup operations. Such operations should never be done without good justification and must be carefully reviewed for security and compliance purposes.
10. Audit Policy Changes Shows changes to audit policy settings. Audit policy shall be clearly defined in every organization and change only after explicit approval by management.
11. Failed Logon Attempts Shows failed authentication attempts in Active Directory. This report is crucial to security and compliance of every organization.
12. Remote Desktop Sessions Shows remote desktop sessions, initiated, terminates, and reconnected.
13. Security Group Membership Changes Security groups control access to data and resources and all changes must be carefully reviewed on a regular basis in order to ensure overall security and sustain compliance with regulations.
14. Successful User Logons Shows logons made by users. This report is one of the most important security reports and can be used to track user activity during security and compliance reviews.
15. Password Changes by User Shows password changes initiated by regular users as opposed to password resets performed by administrators and help desk operators.
The commercial version of the Event Log Manager is available with advanced functionality and technical support.
The free version supports up to 10 servers. The product also has a commercial version that supports unlimited number of servers, features long-term archiving storage and distributed data collection for highest performance. The long-term archiving of event logs is required by compliance regulations, e.g. SOX and HIPPA require 7 years of data, PCI requires 1 year.
Freeware Version Limitations:
* Archiving and reporting term is one month only
* Limited enterprise-class scalability
The license of this software is Freeware, you can free download and free use this server utility software.

