Subscribe to Windows IT Pro
October 26, 2004 12:00 AM

Event Response

Three event-log monitoring tools that keep your reaction time to a minimum
Windows IT Pro
InstantDoc ID #44093
Rating: (3)

EventTracker
EventTracker uses a fully agent-based architecture, perhaps because it provides other monitoring functionality.

EventTracker supports a wide range of alerting options, including email, command execution, SNMP generation, and pop-ups. EventTracker requires you to have its RemoteViewer component open to receive pop-up alerts. Of the three products, only EventTracker includes an alert console that offers acknowledgement and resolution-notes capability. EventTracker is also the only product that provides threshold alerts.

EventTracker's agent pushes the server's event logs in EVT format to a central file server. Alternatively, it will archive them on each server and provide MD5 hashes of the event logs so that you can prove they haven't been modified after they're archived. Using a proprietary application protocol, EventTracker's agent also sends events to the central console, from which you can run reports. You can configure the console to use UDP or TCP, depending on whether you want less burden on your network (UDP) or guaranteed delivery of events (TCP). The ports are documented, so you can pass data through firewalls if necessary.

EventTracker provides some prebuilt reports for common events. The product lets you create detailed reports or summaries and doesn't require you to write SQL. Also, EventTracker provides links to extra details about specific event IDs through its Web-based event-log knowledge base.

In addition to its event-log monitoring functionality—which you can see in Figure 2—EventTracker has many other built-in monitoring features, providing reports on disk and CPU utilization, disk space, software installation, services, Web site availability, system uptime and downtime. Also, EventTracker provides two-way SNMP support for both monitoring for SNMP messages and generating SNMP messages as an optional alert method. Finally, EventTracker lets you schedule reports for regular execution, followed by automatic email delivery to specified recipients.



EventTracker, Protector Edition
Contact: Prism Microsystems * 410-953-6776
Web: http://www.eventlogmanager.com
Price: $999 for a five-server license
Summary
Pros: EventTracker packs a lot of additional functionality beyond the three core event-log management functions of alerting, archiving, and reporting
Cons: Along with the extra functionality comes a mandatory agent for each server you monitor
Rating: 4 out of 5
Recommendation: Good value for the money, especially if you need to monitor other Windows components besides the Security log and don't mind installing agents on each server.


ServScan
ServScan provides barebones event-log monitoring and alert services but no reporting or log archival features. It's a completely agentless product that can manage remote event logs from one software installation. You can create groups of servers and alert rules so that you don't have to repeatedly redefine your alert logic.

ServScan supports NetBIOS pop-up messages, and, interestingly, ServScan is the only product of the three featured in this comparative review to offer any type of flood prevention. ServScan's only other distinguishing feature is its comprehensive support for sending pages directly via modem. ServScan lets you send alphanumeric pages or numeric-only pages, as Figure 3 shows. Unfortunately, I experienced frequent crashes with the ServScan GUI. However, I had no problems with the service that performs the actual monitoring.



ServScan
Contact: Omnitrend Software * 860-673-8910
Web: http://www.omnitrend.com
Price: $299 for a five-server license
Summary
Pros: If your email infrastructure is down and you need out-of-band paging, ServScan is an option with its healthy pager support
Cons: Among alerting, archiving, and reporting features, ServScan provides only alerting
Rating: 2 out of 5
Recommendation: At $60 a server, ServScan might have you opting for the more substantial functionality of a product such as Event Alarm.


Recommendation
At about $60 a server, ServScan is difficult to recommend even strictly as a monitoring and alert solution. You can spend just a little bit more and get much more functionality, such as Syslog monitoring and the ability to send alerts to a database, with Event Alarm. So the choice essentially comes down to EventTracker and Dorian's suite. But making a recommendation between those two products is difficult because both companies have put a lot of impressive work into their respective products and EventTracker's cost is similar to that of Dorian's suite. Both tools are easy to install and manage. Each product offers unique features that I appreciate. Dorian's modular architecture makes agents optional and lets you report on multiple event logs without requiring a central database. EventTracker packs a lot of functionality above and beyond event-log management—including monitoring text-based log files, performance counters, network ports, and system services—but those features are beyond the scope of this comparative.

If you need to integrate your event-log management solution with other monitoring solutions (or UNIX- or Linux-based systems), or you need to monitor routers and other devices, EventTracker's support of SNMP and Syslog will be important to you. But if you're looking for any combination of best-of-breed event log alerting, reporting, and archiving, Dorian's suite takes the cake. I didn't look at products that focus mainly on the Security log. If you're looking for event-management tools in that arena, check out the tools that Table 2 lists.

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    7 years ago
    Mar 03, 2005

    Dorian's Event Alarm, Event Archiver, and Event Analyst are the best products on the market. We evaluated all of them and then purchased Dorian's products based on performance and reliability.

  • harry-o
    8 years ago
    Oct 26, 2004

    If you want a great agentless monitoring solution, I just came across this new company called Integrien. Their product does network and application monitoring. Great dashboard too.

  • harry-o
    8 years ago
    Oct 26, 2004

    If you want a great agentless monitoring solution, I just came across this new company called Integrien. Their product does network and application monitoring. Great dashboard too.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.