Windows Event Log – email notification

alertingwindowswindows-event-log

Is there an easy way to send an email when a particular severity of event from a particular service hits the Windows server event log? This is on Windows Server 2003, if it makes a difference.

n.b. we do have proper monitoring and alerting in place for production servers at my workplace, but we just a need quick solution for this service in development.

Best Answer

You could do this with OSSEC, a multi-platform open-source software:

OSSEC is a full platform to monitor and control your systems. It mixes together all the aspects of HIDS (host-based intrusion detection), log monitoring and SIM/SIEM together in a simple, powerful and open source solution.

And for Log Monitoring/Alerting:

Real-time and Configurable Alerts

OSSEC lets customers configure incidents they want to be alerted on which lets them focus on raising the priority of critical incidents over the regular noise on any system. Integration with smtp, sms and syslog allows customers to be on top of alerts by sending these on to e-mail and handheld devices such as cell phones and pagers.

[...]

Every operating system, application, and device on your network generate logs (events) to let you know what is happening. OSSEC collects, analyzes and correlates these logs to let you know if something wrong is going on (attack, misuse, errors, etc).

Hereis an article about OSSEC on 360° Security.


Specialized, commercial alternative: EventTracker (Prism Microssystems):

EventTracker is a complete Security Information and Event Management (SIEM) solution that combines real-time Log Management with powerful Configuration and Change Management in one turnkey software package.