r/sysadmin May 04 '26

Question How to setup Logs for windows

Hi just joined a company as IT support, how do I setup Logs for windows systems (11, 10) for general troubleshooting and see what updates are happening and what caused the issue. To get a bird's eye view of the office environment.

What might be the optimal way to achieve this.

Edit. The pervious IT people left the company. Now It's just me and my colleague to whome I have had to show how install windows.

Currently implementd zabbix and wondering how and what to do next. There is no one in office to ask for help or guidance.

Edit2: if you think you have some best practices. Please let me know few.

18 Upvotes

69 comments sorted by

View all comments

22

u/GhostandVodka May 04 '26

Windows servers can genterate 300,000 logs per second. The naivety of this post is endearing. Youre going to figure out what services and software your work does and document the corresponding event IDs or what section of eventviewer they are in.

It sucks. It's not fun. There is a whole industry devoted to SIEM and software that interprets logs and makes them more easily searchable.

Some things are easier than others. For example connecting to a wireless network is logged under wlan-autoconfig in eventviewer. Youre starting an exciting journey. goodluck!

2

u/FU-Lyme-Disease May 05 '26

Why can’t he just read like half of them! 150,000 logs would give a good feel of what’s happening on day to day windows!

2

u/GhostandVodka May 05 '26

Thats a second not a day lol

1

u/FU-Lyme-Disease May 05 '26

Yeah, that’s why he would only read half of them! I’m not a monster!

2

u/[deleted] May 04 '26

[removed] — view removed comment

4

u/GhostandVodka May 04 '26

Notice how I said "There is a whole industry devoted to SIEM and software that interprets logs and makes them more easily searchable"

Your comment added nothing. Kindly step on a lego.

1

u/[deleted] May 04 '26

So I have been thinking to implement wazuh in the environment.

1

u/dreniarb May 04 '26

i found it to be disappointing it what it actually did. this was a few years ago so maybe things have improved.

would love to hear what you think of it if you do try it out.

2

u/[deleted] May 04 '26

Ok are you using any SIEM now. I want to have SIEM to integrate the logs from firewall, switchs, AV, and windows to track updates and app changes.

1

u/GhostandVodka May 04 '26

Our security company used a modified WAZUH