| | | Junior Member
       
Group: Forum Members Last Login: 8/12/2009 3:48:02 PM Posts: 18, Visits: 64 |
| I have a bunch of virtual servers running Win2K3, and I've stuck passive Windows Event monitors on them in WUG to alert me when they're being shut down or rebooting (Event ID = 1074). The idea is I'd like to see an email alert with the username performing the shutdown and the reason they have entered, it should all show up in the payload.
The problem is, it doesn't work. I think it's because the VM's shutdown so fast, they can lose ping as little as 3 seconds after filling out the shutdown dialogue.
A couple of ideas I had were 1. Snare to send it as a syslog event, it might be fast enough to beat the shutdown and 2. Have WUG pull the event from the box somehow after it finishes coming back up. The problem with 1 is it's inelegant to have to throw Snare on a bunch of VMs for that purpose alone, and it still might not work. 2 is only useful for reboots but won't help me if the box is shutdown.
Anybody got helpful input, scripts, anything? |
| | | | Junior Member
       
Group: Forum Members Last Login: 8/12/2009 3:48:02 PM Posts: 18, Visits: 64 |
| | Syslogging with Snare doesn't seem to do the trick either. I can get a report that the machine is shutting down out of the security log, but I can't get the 1074 from the system log that shows the username and reason which is what is needed. |
| | | | Junior Member
       
Group: Forum Members Last Login: 8/12/2009 3:48:02 PM Posts: 18, Visits: 64 |
| | Any help out there? Surely I'm not the only one wanting to do this. |
| | | | Junior Member
       
Group: Forum Members Last Login: 8/12/2009 3:48:02 PM Posts: 18, Visits: 64 |
| Nevermind, it turns out my solution worked, I just had a flaw in the way I was testing it. When I reboot a server I get this:
exchange.xyz.org is being rebooted or shutdown. Log follows:
The process Explorer.EXE has initiated the restart of computer ACU-EXCHANGE on behalf of user XYZ\admin for the following reason: Other (Planned)
Reason Code: 0x85000000
Shutdown Type: restart
Comment: Rebooting Exchange to see if it helps the Blackberries. -- Curtis |
| |
|
|