Getting HostMon and the extended logs on Windows 2012r2

All questions related to installations, configurations and maintenance of Advanced Host Monitor (including additional tools such as RMA for Windows, RMA Manager, Web Servie, RCC).
Post Reply
david.matthewson
Posts: 78
Joined: Tue Oct 24, 2006 12:45 pm

Getting HostMon and the extended logs on Windows 2012r2

Post by david.matthewson »

I use HostMon to 'read' NT type Sys & App logs on servers and this works fine.

I'd like to get it read the 'extended' logs that Windows servers have, but can't see how.

Alex - is this even possible? If not can it go on the wish list for 11.x?

Image
KS-Soft
Posts: 12821
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

NT Event Log test method?
I think you just need to switch from Windows NT to Windows Vista mode when setup test (Compatibility option in Test Properties dialog)

Regards
Alex
david.matthewson
Posts: 78
Joined: Tue Oct 24, 2006 12:45 pm

Post by david.matthewson »

KS-Soft wrote:NT Event Log test method?
I think you just need to switch from Windows NT to Windows Vista mode when setup test (Compatibility option in Test Properties dialog)

Regards
Alex
Perhaps - I'm using the classic NT mode as I've never been able to get Vista mode to work...
Image

Image

Image[/url]

First pic is the detailed logs I'd like to get HM to read..

2nd pic is reading logs from a remote W2012r2 box using classic NT mode... but only shows basic logs..

3rd pic is what I get if I try to use Vista mode and point HM at a W2012r2 box as the target..

I'm obviously being a clutz.. what am I missing pls?

Thanks

D
KS-Soft Europe
Posts: 2832
Joined: Tue May 16, 2006 4:41 am
Contact:

Post by KS-Soft Europe »

Windows API, used by "NT mode" does not support "extended" logs.
If HostMonitor is started on Windows 2003 or Windows XP - it will not be able to use newer NT Log API (Windows Vista mode).
What Windows OS do you have installed on HostMonitor system?
david.matthewson
Posts: 78
Joined: Tue Oct 24, 2006 12:45 pm

Post by david.matthewson »

In this case HM is running as a service on a Win2012R2 box but I've seen the same problem (probably me!) when it's run on a Win 2008 x64 box.

Thanks!
KS-Soft Europe
Posts: 2832
Joined: Tue May 16, 2006 4:41 am
Contact:

Post by KS-Soft Europe »

Could you try using FQDN or IP instead of NetBIOS name?

This issue can be cause by Firewall.
If you are using Windows Firewall, you may allow the following rules (e.g. using GPO):
COM+ Network Access (DCOM-In)
Remote Event Log Management (NP-In)
Remote Event Log Management (RPC)
Remote Event Log Management (RPC-EPMAP)
Windows Management Instrumentation (ASync-In)
Windows Management Instrumentation (DCOM-In)
Windows Management Instrumentation (WMI-In)

Some related links:
http://www.computerperformance.co.uk/po ... t_Remoting
https://www.netwrix.com/kb/1291
david.matthewson
Posts: 78
Joined: Tue Oct 24, 2006 12:45 pm

Post by david.matthewson »

Thanks - will try that & revert.
david.matthewson
Posts: 78
Joined: Tue Oct 24, 2006 12:45 pm

Post by david.matthewson »

david.matthewson wrote:Thanks - will try that & revert.
Still investigating this - anomalous result so will dig deeper.

More soon ;}

Thanks

D
Post Reply