Working with Server 2008 Event Viewer工作與Server 2008的事件查看器
A huge number of things are happening at any one time on a server: Users are logging in and accessing files, drives are spinning away, and processors are trying to make sense of it all.大量的事情發生在任何一個時間服務器上:用戶登錄和訪問文件,硬盤的旋轉之外,處理器正在試圖理解這一切。 Each of these instances is considered an event.所有這些情況被認為是一個事件。 Being able to monitor these events and use them to interpret the health of your servers is an important aspect of administering a Windows Server 2008 network.能監測這些活動,並利用它們來解釋的健康您的服務器的一個重要方面是管理一個Windows Server 2008的網絡。
As its name suggests, the Event Viewer is used to view events.正如其名稱所示,事件查看器是用來查看活動。 Although it is more of a passive tool (it doesn't supply you with the real-time data that you see in the Performance Monitor), it does give you access to a great deal of information.雖然它更是一種被動的工具(它不為你提供實時的數據,你看到的性能監視器) ,它讓您存取大量的資料。
You can view the events related to a particular role by selecting that role node in the Server Manager.您可以查看有關的活動特別選擇的作用,這一作用的節點在服務器管理器。 For example, you can view the events related to file services on a file server by clicking the File Services node in the Server Manager node tree.例如,您可以查看有關的活動檔案服務檔案伺服器上按一下文件服務節點中的服務器管理器節點樹。
Although the Server Manager provides quick access to events related to a role, let's take a closer look at the Event Viewer, which can be opened as a separate snap-in.雖然服務器管理器提供了快速訪問有關的活動的作用,讓我們仔細看看事件查看器,可打開作為一個單獨的單元。 The Event Viewer accumulates events in a number of log files: Event Viewer can help you monitor hardware, application, service, and security issues.事件查看器的事件中積累了一些日誌文件:事件查看器可以幫助您監測的硬件,應用,服務和安全問題。
The Event Viewer (Start, Administrative Tools, Event Viewer) provides two main categories of logs: Windows logs and Applications and Services logs.事件查看器(開始,管理工具,事件查看器)提供了兩個主要類別的日誌:的Windows日誌和應用程序和服務日誌。 The Windows logs include the following:在Windows日誌包括以下內容:
• Application log— This log records events about the various applications running on the system. •應用程序日誌,這個日誌記錄事件有關的各種應用程序運行的系統。 The developer typically presets these events in the software.開發商通常預置這些事件中的軟件。 The application log also records alerts configured in the System Monitor.應用程序日誌中還記錄警示配置中的系統監控。
• Security log— This log records events related to the audit policies that you configure in Group Policy, "Deploying Group Policy and Network Access Protection"), such as the auditing of file access or the logon of a particular user or group of users. •安全日誌,這個日誌記錄有關的活動的審計政策,在您配置組策略“ ,部署組策略和網絡訪問保護” ) ,如審計檔案存取或登錄某個特定的用戶或組的用戶。 This log also tracks events related to resource use (such as files) on the network shares.這個記錄也追踪事件有關的資源使用(如文件)的網絡股。
• Setup log— This log records events related to application installation and setup. •安裝日誌,這個日誌記錄有關的活動申請安裝和設置。 This includes events regarding the adding or removal of server roles, information events when a role is added successfully, and warning events when a restart is necessary to finalize the addition of a role.這包括有關的事件添加或刪除服務器角色,信息的事件時的作用是添加成功,並警告事件時有必要重新啟動完成增加了一定的作用。
• System log— This log provides log entries based on a number of Windows Server 2008 presets. •系統日誌,該日誌提供日誌條目的基礎上了一些Windows Server 2008的預置。 This includes information on things such as driver failures and services that fail to load.這包括信息的東西,如司機的失敗和服務不能負荷。 Anything to do with services or system resources can show up in this log.任何與服務或系統資源,可以顯示在此記錄。
A new set of logs, the Applications and Services logs, provide event logging for individual applications and server components.一套新的日誌,應用程序和服務日誌,事件日誌提供的個人應用程序和服務器組件。 The default Application and Services logs include the Hardware Events (events related to hardware installation and failure), Internet Explorer (Internet Explorer–specific events) and Key Management Service (which is related to the use of encryption keys when sending and receiving data to other computers on the network).默認的應用程序和服務記錄包括硬件事件(事件相關的硬件安裝和故障)時, Internet Explorer ( Internet Explorer中的具體事件)和密鑰管理服務(這是有關使用加密密鑰時,發送和接收數據,其他計算機網絡上) 。 Other logs available in this category depend on the software and roles installed on the server.其他日誌可在這一類依賴於軟件和作用在服務器上安裝。
A system of icons is used to classify the type of event that has been recorded in a particular event log.一個系統的圖標是用來劃分類型的事件,已記錄在一個特定事件日誌。 In the System log and the Application log, you can find the following event categories (each represented by a different icon in the Event Viewer):在系統日誌和應用程序日誌,您可以找到下列事件類別(每個代表一個不同的圖標,事件查看器) :
• The Information icon— Denotes the logging of successful system events and other processes •信息圖標是指伐木的成功系統事件和其他進程
• The Warning icon— Shows a noncritical error on the system •的警告圖標,顯示了非臨界錯誤的系統
• The Error icon— Indicates the failure of a major function (such as a driver failure) •錯誤圖標指示失敗的一個主要功能(如驅動程序故障)
To view a specific log in the Event Monitor, select the log's node in the node tree.要查看特定的日誌事件監控,選擇日誌的節點的節點樹。 The events recorded in that log appear in the Details pane.這些事件記錄在該日誌出現在詳細資料窗格中。
Two additional icons are found in the Security log:另外兩個圖標中發現的安全日誌:
• The Success Audit icon— Shows that a security access event was successful (such as the access of a certain folder or file on the network) •成功審計圖標顯示,安全訪問活動是成功的(如獲得一定的文件或文件夾在網絡上)
• The Failure Audit icon— Shows that an audited security event failed (such as the failure of a user logon) •失效審計圖標顯示,審計安全事件失敗(如失敗,用戶登錄)
To view the properties of a particular event in a log, double-click on the event's icon in the Details pane.要查看的屬性在特定事件日誌,雙擊事件的圖標在詳細資料窗格中。 For example, you may want to see the details related to an Error event logged in the System log.例如,您可能會希望看到相關信息的錯誤事件記錄在系統日誌中。
Microsoft now provides event-specific help for logged events.微軟現在提供了活動的具體幫助記錄的事件。 For more information on a logged event, click the Event Log Online Help link in the event's Properties dialog box.如需詳細資料,記錄的事件,請按一下事件日誌在線幫助鏈接事件的屬性對話框。 You are informed that the Event Viewer will send the information related to the event over the Internet.您正在獲悉,事件查看器將發送相關信息的事件在互聯網上。 Click Yes to continue.單擊是繼續。
Internet Explorer opens and provides additional information on the event. Internet Explorer將打開,並提供額外的信息事件。 This information includes an explanation of the event and possible actions to be taken to remedy the problem related to the event.這些資料包括解釋事件和可能採取的行動糾正問題有關的活動。
Source of Information : Sams Teach Yourself Windows Server 2008 in 24 Hours 信息來源:薩姆斯自學Windows Server 2008的24小時
Written by magakos. 撰稿magakos 。 Read more great feeds at is source 閱讀更多的是供稿源 WEBSITE 網站
no comments 沒有評論 . 。
Read more articles on 閱讀更多文章 MIcrosoft Windows Server 2008 微軟Windows Server 2008的 and 和 otherSoftware otherSoftware . 。
- [+] Digg [ + ] Digg的 : Feature this article :特徵本文
- [+] Del.icio.us [ + ] Del.icio.us : Bookmark this article : 06條
- [+] Furl [ + ]卷 : Bookmark this article : 06條















