Home > Ask the Enterprise Desktop Experts > Questions & Answers > Archiving versus overwriting
Ask The Enterprise Desktop Expert: Questions & Answers
EMAIL THIS

Archiving versus overwriting

Randy Franklin Smith EXPERT RESPONSE FROM: Randy Franklin Smith

Pose a Question
Other Enterprise Desktop Categories
Meet all Enterprise Desktop Experts
Become an Expert for this site
>
QUESTION POSED ON: 12 October 2004
My Windows 2000 Security Log is approaching full capacity. I'm debating whether to archive the security log or overwrite it. Do you have any suggestions about which option is better? Thanks.

>
EXPERT RESPONSE

That decision should ultimately be driven by your company's written security policy, but in general, the first thing to consider is how far back you want to be able to go as far as audit trails and investigations? Compare that to how far back your log goes with its current size limit. Depending on how much activity gets logged every day, you may be able to keep several months of activity online and just allow the log to overwrite as necessary. However, without archiving the security log you lose some ability to respond to and recover from attacks. If an attacker succeeds in gaining sufficient authority to your system, one of the first things he will do is clear the logs to hide details of his intrusion. Therefore, for best security, you should ideally archive logs to a separate and secure server as frequently as possible.

You can do this yourself by scheduling a script that runs dumpel (a resource kit utility), or there are plenty of security log products that provide archival functionality and more, including Dorian's EventArchiver, GFI's LANGuard SELM, Sentry II from EngageNT and EventTracker from Prism Microsystems.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Desktop Solutions - Windows for Enterprise
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts