0%

0/1 Lessons

Course Introduction

• 10min

0 / 2 lessons complete

DNS Basics

• 1hr 16min

0 / 8 lessons complete

DNS Resource Records

• 46min

0 / 5 lessons complete

DNS Zones

• 3hr 41min

0 / 12 lessons complete

DNS Delegation

• 50min

0 / 4 lessons complete

DNS Security Techniques

• 36min

0 / 5 lessons complete

Advanced DNS Topics

• 22min

0 / 5 lessons complete

DNS Security (DNSSEC)

• 1hr 16min

0 / 6 lessons complete

DNS Policies

• 54min

0 / 6 lessons complete

PowerShell for DNS

• 1hr 27min

0 / 6 lessons complete

Troubleshooting DNS Issues - Troubleshooting Tools

• 1hr 39min

0 / 8 lessons complete

The Events Viewer Overview

Instructions

Q&A (0)

Notes (0)

Resources (0)

Saving Progress...

Resources

There are no resources for this lesson.

Notes can be saved and accessed anywhere in the course. They also double as bookmarks so you can quickly review important lesson material.

Create note

In this Video: 

  • We will present an overview of the Windows Event Viewer.
  • At the completion of this lecture you will gain valuable-work related knowledge and experience by utilizing and implementing the tools discussed in this lecture.

The Event Viewer has been vastly improved over the earlier versions of the Windows operating systems. In this lecture, you will become familiar with the new features of this event viewer. If you need to troubleshoot problems the logs and the events ID’s viewer is where you will be spending the majority of your time. If you want to be the best, learn how to use this event viewer.

To open the event viewer – Use Widows search, type event viewer

In the left panel we have:

  • Event viewer
  • Custom Views  
  • Windows logs
  • Applications and Services Logs
  • Subscriptions

On the right, we have the Summary of Administrative Events, which is an overview of all event types. Also the Events that you may need to pay attention to right away will be in the summary.  

For example, In this case, click the + sign by critical, double click kernel-power

(The kernel power event ID 41 error occurs when the computer is not shut down cleanly, server locked up) 

Go back to the summary page, in this case, click the + sign by errors, double click event ID 404 DNS-Server-Service, double click the last error 

Recently viewed nodes: - which displays the last viewed log files

Log Summary: This summary displays the retention policy. This policy is based upon answers to the following question. When this log reaches a certain size what do you want to do?

  • Overwrite events
  • Archive events
  • Clear logs manually

If you open windows logs, right click on the application log, then properties. You will see the default settings for the log size and the three choices, overwrite, archive or clear the logs manually.

These settings become important when you start getting low on hard disk space, or your network is getting bogged down moving data between servers from all the misconfigured logs.

  • Event Viewer (Local)  

Right click, here you can connect to another Computer. In this case, I type SVR-DNS1 and can view all the logs and events.

• Custom Views 

 

Creating a custom view: You can create a filter that includes events from multiple event logs that satisfies specified criteria. You can then name and save that filter as a custom view. Let’s say you are having a DNS problem on your DNS server you can configure a custom view for troubleshooting that particular issue.

Let’s create a Custom view for my DNS server SVR-US.  

  • Right click on custom views, select create custom view
  • Check critical, then check error
  • Select By source, click the down arrow, scroll down and select DNS-Server  
  • select down arrow on Task category: Click <All Task Categories>
  • Click the down arrow on Keywords: select <All Keywords>
  • Click ok, Name – I type SVR-US Events
  • Server Rolls â€“ If you have installed a server roll, there will be an event displayed here by default.

Active Directory Domain Services â€“ Shows all the system events for Active Directory Domain Services.

DNS Server - Displays the System events for DNS Server

Remote Desktop Services â€“ Displays the System events for Remote Desktop Services

• Windows logs

Application log  

An application log is a file of events that are logged by a software application. It contains errors, informational events, and warnings. Such as the failure of MS SQL to access a database.

Security log

A Security log is a log that contains records of login/logout activity or other securityrelated events  

Server Academy Members Only

Sorry, this lesson is only available to Server Academy Full Access members. Become a Full-Access Member now and you’ll get instant access to all of our courses.

0 0 votes
Lesson Rating
Subscribe
Notify of
profile avatar
3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

profile avatar
dewitsc(@dewitsc)
Member
1 year ago

I do not have the documentation for the “source initiated subscription” for this lesson. Can you please help with that?

profile avatar
Ricardo P(@ricardop)
Admin
Reply to  dewitsc
1 year ago

Hi profile avatar Dewits Cham

The information Robert is referring to is on the following Microsoft Link:
https://learn.microsoft.com/en-us/windows/win32/wec/setting-up-a-source-initiated-subscription

Ricardo

profile avatar
dewitsc(@dewitsc)
Member
Reply to  Ricardo P
1 year ago

Thank you and sorry for the late reply!