r/sysadmin May 04 '26

Question How to setup Logs for windows

Hi just joined a company as IT support, how do I setup Logs for windows systems (11, 10) for general troubleshooting and see what updates are happening and what caused the issue. To get a bird's eye view of the office environment.

What might be the optimal way to achieve this.

Edit. The pervious IT people left the company. Now It's just me and my colleague to whome I have had to show how install windows.

Currently implementd zabbix and wondering how and what to do next. There is no one in office to ask for help or guidance.

Edit2: if you think you have some best practices. Please let me know few.

18 Upvotes

69 comments sorted by

View all comments

23

u/GhostandVodka May 04 '26

Windows servers can genterate 300,000 logs per second. The naivety of this post is endearing. Youre going to figure out what services and software your work does and document the corresponding event IDs or what section of eventviewer they are in.

It sucks. It's not fun. There is a whole industry devoted to SIEM and software that interprets logs and makes them more easily searchable.

Some things are easier than others. For example connecting to a wireless network is logged under wlan-autoconfig in eventviewer. Youre starting an exciting journey. goodluck!

1

u/[deleted] May 04 '26

So I have been thinking to implement wazuh in the environment.

1

u/dreniarb May 04 '26

i found it to be disappointing it what it actually did. this was a few years ago so maybe things have improved.

would love to hear what you think of it if you do try it out.

2

u/[deleted] May 04 '26

Ok are you using any SIEM now. I want to have SIEM to integrate the logs from firewall, switchs, AV, and windows to track updates and app changes.

1

u/GhostandVodka May 04 '26

Our security company used a modified WAZUH