WMI query fails to find a security event by its record number


hello all!

i'm having strange issue when trying perform queries wbemtest in remote server 700.000 security events.

when try query:

select * win32_ntlogevent logfile = "security"

it starts showing security events on remote server. when choose recent 1 (for example record number: 310137481) , try search record number:

select * win32_ntlogevent logfile = "security" , recordnumber = 310137481

i don't have results.

instead, if filter query attribute (like event type), throws events attribute. seems issue related recordnumber.

just in case it's useful, server generating around 300.000 security events in 13 minutes (so takes 30 minutes event disappear event log).

is there kind of limitation wmi doesn't allows find event in such big event log?



hi,

this english language forum. might want post query in technet spanish forum

(este es un foro de idioma inglés. es posible que desee crear esta consulta en español haga clic aquí para foro)

http://social.technet.microsoft.com/forums/es-es/windowsserveres/threads


i not represent organisation work for, opinions expressed here own.

this posting provided "as is" no warranties or guarantees , confers no rights.

- .... .- -. -.- ... --..-- ... .- -. - --- ... ....





Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client