i am trying to use LogParser utility for producing reports
on some security inidents but i am facing few difficulty
to understand the syntax
for example if i want to filter only few EventID by
TimeWritten that's mean by date and to output to XML or
IIS.
Any advice?
Thanks In Advanced
Not sure exactly what you're asking, but this works for me: -
logparser file:query.sql -i:IISW3C -o:CSV >results.csv -stats:OFF
Where the content of query.sql is: -
SELECT *
FROM *.log
WHERE date = '2003-03-24'
AND time >= '06:00:00' AND time <= '08:00:00'
--
Ritchie