Windows – Good Windows event log analyzing/reporting tool


I'm looking for a Windows eventlog analyzing and monitoring software for Windows Server 2000/2003 (there are some new features in Windows Server 2008.) The feature set should include:

  • real-time monitoring (alerts via email or other messages)
  • definition of events/event groups which are watched
  • multiple-server
  • reporting (daily/weekly etc. reports)
  • nice client tools
  • not necessarily free or open-source, but that would be nice (of course)

Any recommendation or tip how to implement this using standard tools?


Best Answer

I would suggest you use OSSEC. It can agregate all the information in a single server and has a nice web interface that allows you to display the alerts.