Ask the Community
Groups
Agent procedure to Collect Windows Event Logs - Application and System Logs - Connect IT Community | Kaseya
<main> <article class="userContent"> <p>PROBLEM:</p> <p>If asked to collect Windows Event logs to further investigate an issue. This procedure can be used to facilitate this process. </p> <p>This procedure saves system and application event logs to .evt files using shell commands, zips them using 7-zip command line version, and uploads to the Get File area on the kserver.</p> <p> </p> <p>SOLUTION:</p> <p>To use this procedure: </p> <p> </p> <p>1) download 7zip command line version from <a rel="nofollow" href="/home/leaving?allowTrusted=1&target=http%3A%2F%2Fdownloads.sourceforge.net%2Fsevenzip%2F7za920.zip">http://downloads.sourceforge.net/sevenzip/7za920.zip</a></p> <p>2) go to Agent Procedures > Schedule/Create and click the Managed Files button - upload 7za.exe to the Shared area</p> <p>3) extract the attached file Procedure Get event logs.xml and create procedure using the Import Folder/Procedurebutton</p> <p>4) after running the procedure, the event log files will be available from the Agent Procedures > Get Files function (eventlogs.zip)</p> <p> </p> <p> </p> <p> </p> <p> </p> </article> </main>