And second things is great that you also import a list of servers from a text-file. See the screenshots below. How to use the EventCombMT utility to search event logs for account lockouts.
Office Office Exchange Server. Not an IT pro? Date Published:. File Size:. System Requirements Supported Operating System. Install Instructions Click the Download link to start the download. In the File Download dialog box, select Save this program to disk.
Select a location on your computer to save the file, and then click Save. You can download EventComb free of charge from Microsoft's website. Simply go to www. On the home page for this guide, click the Downloads link and download all the scripts associated with this guide.
Then extract the downloaded file. Once extracted, you'll find the EventComb tool inside the EventComb folder. There is no installation per se for this tool. It's merely an executable that runs when invoked. To run EventComb, double-click the evencombmt. Figure After starting this tool, the first step is to add the computers that you want to include in the event log search. To add computers to the search, follow these steps:. In the EventComb utility, ensure that the correct domain appears in the Domain box.
If it does not, enter the correct domain name. Notice that you can select from a variety of servers based on their role, name, domain affiliation, or a list derived from a file. You can also select servers that appear in this box and remove them from the target list.
Once the desired servers are added, you must select the servers in the list against which to perform your search. Hence, servers can appear in the list but not be searched for a particular query.
What this means is that when the tool is initially run, you need to select the servers that you wish to mine two times: once to get them into the list and a second time to include them in the search query. After you select the servers to be included in your search, you are ready to specify the search criteria, which includes the following:.
By combining these elements, you can pinpoint your search to yield the best and most helpful information possible. While the search is running see Figure
0コメント