March 27, 2022, 3:08 a.m. | /u/Jonathan-Todd

cybersecurity www.reddit.com

How are you guys pulling Windows Event Log data from any significant number of hosts for security investigations if a client didn't enable event log forwarding? I have spent my entire day looking for a solution to this.

I know you can do it through the Event Viewer GUI, but that's really not viable for pulling from hundreds of hosts. I have gone to StackOverflow, ServerFault, friends, colleagues, no one seems to know a way to do this. It seems …

copy cybersecurity event event logs forwarding log logs windows windows event logs

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cloud Technical Solutions Engineer, Security

@ Google | Mexico City, CDMX, Mexico

Assoc Eng Equipment Engineering

@ GlobalFoundries | SGP - Woodlands

Staff Security Engineer, Cloud Infrastructure

@ Flexport | Bellevue, WA; San Francisco, CA

Software Engineer III, Google Cloud Security and Privacy

@ Google | Sunnyvale, CA, USA

Software Engineering Manager II, Infrastructure, Google Cloud Security and Privacy

@ Google | San Francisco, CA, USA; Sunnyvale, CA, USA