<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">システム管理な雑記 -- Sleeve notes of a sysadmin --</title><subtitle type="html">About system management, languages, and miscellaneous things from my daily sysadmin life. Technical and non-tech entries.</subtitle><id>http://msmvps.com/blogs/yamaken/atom.aspx</id><link rel="alternate" type="text/html" href="http://msmvps.com/blogs/yamaken/default.aspx" /><link rel="self" type="application/atom+xml" href="http://msmvps.com/blogs/yamaken/atom.aspx" /><generator uri="http://communityserver.org" version="4.0.30619.63">Community Server</generator><updated>2004-01-29T23:18:00Z</updated><entry><title>Note: Migrating existing user profiles to new accounts on Windows machines (XP/2003)</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx" /><id>/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx</id><published>2007-10-08T05:06:00Z</published><updated>2007-10-08T05:06:00Z</updated><content type="html">-- English -- Moving user profiles, which is needed during/after migration from existing environments to Active Directory, is a kind of somewhat tough thing, I mean the amounts of target accounts and time consumed, and some of caveats. Currently we can mainly use the following supported patterns: User Settings Migration Tool(USMT)/Files and Settings Transfer Wizard(FSTW) USMT is for automatic deployment. This tool can migrate profiles settings from the source accounts to the target accounts on the...(&lt;a href="http://msmvps.com/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1239557" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /></entry><entry><title>Misc: Awarded again as MVP.</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2007/10/08/misc-awarded-again-as-mvp.aspx" /><id>/blogs/yamaken/archive/2007/10/08/misc-awarded-again-as-mvp.aspx</id><published>2007-10-08T03:26:00Z</published><updated>2007-10-08T03:26:00Z</updated><content type="html">--English-- Thanks to everyone involved, I am awarded again as an MVP, 6th or 7th time in a row. (Well, I am not sure which is correct. ) I received MVP awards in the following order: Security (2002.07-2002.09; this may not be an official one) Security (2002.10-2003.09) Windows Server Systems Security (2003.10-2004.09) Windows Security (2004.10-2005.09) Windows Security (2005.10-2006.09) Windows Security (2006.10-2007.09) Windows Security (2007.10-2008.09) My first opportunity as an MVP came when...(&lt;a href="http://msmvps.com/blogs/yamaken/archive/2007/10/08/misc-awarded-again-as-mvp.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1239153" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /></entry><entry><title>日本語テスト... /test posting in Japanese</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2007/10/07/test-posting-in-japanese.aspx" /><id>/blogs/yamaken/archive/2007/10/07/test-posting-in-japanese.aspx</id><published>2007-10-08T01:40:00Z</published><updated>2007-10-08T01:40:00Z</updated><content type="html">----Japanese---- 日本語での投稿テストです。日本語が使えることが確認できたので、日本語と英語の両方で投稿してみよう。この投稿では、日本語を先、英語をその次、の順番で。 ---- English ---- This is just a test post in Japanese. As I confirmed that we can use Japanese, I am going to post articles both in Japanese and English. Japanese first, then English texts follow, for this post....(&lt;a href="http://msmvps.com/blogs/yamaken/archive/2007/10/07/test-posting-in-japanese.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1238251" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /></entry><entry><title>Awarded Again</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/10/03/14733.aspx" /><id>/blogs/yamaken/archive/2004/10/03/14733.aspx</id><published>2004-10-03T11:16:00Z</published><updated>2004-10-03T11:16:00Z</updated><content type="html">&lt;P&gt;Today I have signed up for the MVP program for another one year. This time I am awarded for Windows Security, as it seems the category I got awarded, "Windows Server Systems Security", does not currently exist.&lt;/P&gt;
&lt;P&gt;Whew, there are really bunch of famous and cool people in the category...&lt;/P&gt;
&lt;P&gt;I have also found a good thing. Japanese MVPs specialized in Windows Security has increased in number.&lt;/P&gt;
&lt;P&gt;Here are Japanese Security MVPs whom I know:&lt;/P&gt;
&lt;TABLE cellSpacing=0 cellPadding=4 border=1&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Name&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Web Site in Japanese&lt;BR&gt;(pls open up your favorite translator when you browse any of these sites below...)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Hideaki Ihara&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;One of the most active people in Japan. Specializes in security in general. Broad knowledge.&amp;nbsp;His strongest interest nowadays seems forensics.&lt;/P&gt;
&lt;P&gt;Port139 &lt;A href="http://www.port139.co.jp/" target=_blank&gt;http://www.port139.co.jp/&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Hajime Kojima&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;His site is a kind of hub of info regarding security, FreeBSD, Linux, and Windows.&lt;/P&gt;
&lt;P&gt;Security Hole Memo &lt;A href="http://www.st.ryukoku.ac.jp/~kjm/security/memo/" target=_blank&gt;http://www.st.ryukoku.ac.jp/~kjm/security/memo/&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Michio Sonoda&lt;/TD&gt;
&lt;TD&gt;An active expert in several of communities. Specializes in security policies in general.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Akira Ryowa&lt;/TD&gt;
&lt;TD&gt;An active expert in several of communities. Specializes in PKI, encryption, penetration tests, and so on...&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Hidenobu Seki&lt;BR&gt;(aka. &lt;A href="http://www.blackhat.com/html/win-usa-02/win-usa-02-spkrs.html#Urity" target=_blank&gt;Urity&lt;/A&gt;)&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Specializes in authentication process concerning Windows. NTLM, DCOM, RPC, for example. &lt;A href="http://www.blackhat.com/html/win-usa-03/win-usa-03-speakers.html#Yoshiaki%20Komoriya" target=_blank&gt;A regular speaker in Black Hat Briefings.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Security Friday &lt;A href="http://www.securityfriday.com/" target=_blank&gt;http://www.securityfriday.com/&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Kaoru Yoshida&lt;/TD&gt;
&lt;TD&gt;A trainer of "Legend" for various and many of technologies and products around Windows and server products of Microsoft. MOM and DRM are&amp;nbsp;what he is currently into. He had sessions at &lt;A href="http://www.event-registration.jp/events/te04/" target=_blank&gt;TechED 2004 Yokohama (in Japan)&lt;/A&gt;.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Yuu Arai&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;One of Japanese regular reporters of vulnerabilities to MSRC. (MS02-023.062, and so on...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Specializes in client-side things, it seems.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Tsuneyoshi Hamamoto&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Specializes in network and security. A founder and moderator of a mailing list called "connect 24h" in which many of interesting topics are found.&lt;/P&gt;
&lt;P&gt;Banquet of broad band connection &lt;A href="http://cn24h.hawkeye.ac/" target=_blank&gt;http://cn24h.hawkeye.ac/&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Kunio Miyamoto&lt;BR&gt;(aka. wakanoto)&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;An IPSec and WebDAV guy.&amp;nbsp;A character. &lt;A href="http://www.atmarkit.co.jp/misc/search/search.php" target=_blank&gt;A regular poster in a site called @IT&lt;/A&gt;, and also an editor at &lt;A href="http://slashdot.jp/authors.shtml" target=_blank&gt;SlashDot Japan&lt;/A&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=14733" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /></entry><entry><title>Honeynet Security Console</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/16/6546.aspx" /><id>/blogs/yamaken/archive/2004/05/16/6546.aspx</id><published>2004-05-16T23:36:00Z</published><updated>2004-05-16T23:36:00Z</updated><content type="html">&lt;p&gt;From &lt;a title="seculogger" href="http://www.7th-angel.net/seculog/" target="_blank"&gt;seculogger&lt;/a&gt;'s &lt;a href="http://www.7th-angel.net/seculog/item/548.html" target="_blank"&gt;blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.activeworx.org/programs/hsc/index.htm"&gt;Honeynet Security Console&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It seems very neat. I decided that I should evaluate this, with &lt;a href="http://project.honeynet.org/tools/sebek/" target="_blank"&gt;sebek!&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6546" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /><category term="Security tips" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx" /><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Interoperability" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /></entry><entry><title>Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/10/6148.aspx" /><id>/blogs/yamaken/archive/2004/05/10/6148.aspx</id><published>2004-05-10T15:16:00Z</published><updated>2004-05-10T15:16:00Z</updated><content type="html">&lt;p&gt;This webcast covers topics around "how to use the recovery console" and more about troubleshooting the boot phase. It is a must thing, you know, as we engineers handle issues around servers. ;-)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=/servicedesks/webcasts/en/wc062502/wct062502.asp" target="_blank"&gt;Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6148" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Security tips" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>Note: [IIS] How to have NNTP Feed?</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/09/6118.aspx" /><id>/blogs/yamaken/archive/2004/05/09/6118.aspx</id><published>2004-05-09T22:01:00Z</published><updated>2004-05-09T22:01:00Z</updated><content type="html">&lt;p&gt;From Bernard's article.&lt;br /&gt;&lt;a id="_ctl0__ctl2_TitleUrl" href="/bernard/posts/4455.aspx" target="_blank"&gt;Errors in IIS 6.0 Documentation&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I have once tested this NNTP Feed feature of IIS 6.0, with Shavlik's news server. &lt;br /&gt;It seems I have to dig more on this.;-)&lt;/p&gt;
&lt;p&gt;Thanks, Bernard!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6118" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>JAPAN: Personal and private information in danger?</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/09/6117.aspx" /><id>/blogs/yamaken/archive/2004/05/09/6117.aspx</id><published>2004-05-09T21:54:00Z</published><updated>2004-05-09T21:54:00Z</updated><content type="html">&lt;p&gt;From &lt;a href="http://www.7th-angel.net/seculog/" target="_blank"&gt;seculogger&lt;/a&gt;, another Japanese MVP.&lt;br /&gt;&lt;a href="http://www.7th-angel.net/seculog/item/550.html" target="_blank"&gt;http://www.7th-angel.net/seculog/item/550.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;According to NHK, a leading broadcasting company in Japan, about 38% of market-leading companies in Tokyo Stock Exchange Market stated that they do not and will not have|prepare rules to prevent the outflow of private information.&lt;br /&gt;Src (Pls use babelfish to have them translated):&lt;br /&gt;&lt;a href="http://www3.nhk.or.jp/news/2004/05/09/k20040508000025.html" target="_blank"&gt;http://www3.nhk.or.jp/news/2004/05/09/k20040508000025.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.asahi.com/national/update/0508/012.html" target="_blank"&gt;http://www.asahi.com/national/update/0508/012.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;* Babelfish:&lt;br /&gt;&lt;a href="http://babelfish.altavista.digital.com/babelfish/tr" target="_blank"&gt;http://babelfish.altavista.digital.com/babelfish/tr&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I do not understand what these companies have in mind, as the privacy law will be enforced in the next year. This means all the companies should be careful and does have responsibility enough to prevent such a thing, otherwise it is each of these companies' fault. I wonder where people in this country are heading for...?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6117" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /><category term="Security bleaches..." scheme="http://msmvps.com/blogs/yamaken/archive/tags/Security+bleaches_2E00__2E00__2E00_/default.aspx" /></entry><entry><title>Tool: Quest Software Quest Central (Freeware)</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/10/tool-quest-software-quest-central-freeware.aspx" /><id>/blogs/yamaken/archive/2004/05/10/tool-quest-software-quest-central-freeware.aspx</id><published>2004-05-09T21:36:00Z</published><updated>2004-05-09T21:36:00Z</updated><content type="html">&lt;p&gt;From &lt;a href="http://sqljunkies.com/News/0059AB25-88B2-445C-9A95-2278E067E10A.scuk" target="_blank"&gt;SQLJunkies.&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Quest Software Quest Central for SQL SERVER - FREEWARE Now Available&lt;br /&gt;&lt;a href="http://www.quest.com/quest_central/sql_server/freeware/" target="_blank"&gt;http://www.quest.com/quest_central/sql_server/freeware/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It&amp;nbsp;features things like this:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Database Administration &lt;/li&gt;
&lt;li&gt;Space Management &lt;/li&gt;
&lt;li&gt;24x7 Monitoring &lt;/li&gt;
&lt;li&gt;Performance Diagnostics with Spotlight &lt;/li&gt;
&lt;li&gt;Database Analysis &lt;/li&gt;
&lt;li&gt;Load Testing and Data Generation&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Hmm, sounds not too bad, you know.&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6115" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /></entry><entry><title>Tool: Syslog Turbo, DHCP Turbo, etc.</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/10/tool-syslog-turbo-dhcp-turbo-etc.aspx" /><id>/blogs/yamaken/archive/2004/05/10/tool-syslog-turbo-dhcp-turbo-etc.aspx</id><published>2004-05-09T19:48:00Z</published><updated>2004-05-09T19:48:00Z</updated><content type="html">&lt;p&gt;Softwares from Weird-Solution seems somewhat cool.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.weird-solutions.com/" target="_blank"&gt;http://www.weird-solutions.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As for Syslog Turbo there are things that is helpful for daily sysadmin jobs, like analysis and log rotation features. We can manipulate it with a sql-like dialect, which may be fairly useful as long as you are familiar with SQL.&lt;/p&gt;
&lt;p&gt;There are other easy-to-manipulate server softwares like DHCP, BOOTP, and TFTP so please check them out.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6100" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /></entry><entry><title>Tool: ieSpell</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/09/tool-iespell.aspx" /><id>/blogs/yamaken/archive/2004/05/09/tool-iespell.aspx</id><published>2004-05-09T08:25:00Z</published><updated>2004-05-09T08:25:00Z</updated><content type="html">&lt;p&gt;A spell checker for IE. I found it when I did some spell-checks on the previous article. This tool is for English only, it seems. Still, it is very cozy.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.iespell.com/" target="_blank"&gt;ieSpell - A Spell Checker for Internet Explorer&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6086" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /></entry><entry><title>Just a note of log consolidation issues.</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/08/6082.aspx" /><id>/blogs/yamaken/archive/2004/05/08/6082.aspx</id><published>2004-05-09T04:13:00Z</published><updated>2004-05-09T04:13:00Z</updated><content type="html">&lt;p&gt;There are numbers of tasks around sysadmins and security engineers at the data centers, which include log management and monitoring the servers/clients to check if there is an unusual thing happening/ongoing. &lt;/p&gt;
&lt;p&gt;I have begun to think of this one year ago when around me there were many of "untouched" or unmanaged as for the system environment. With such a server, when a trouble happens there is no one who could trace what is wrong or what should be done, or worse, when the box downs. It is not cool....&lt;/p&gt;
&lt;p&gt;So, to trace the anomalies I am now heading in log consolidation/management to have evidence enough for troubleshooting and detection of problems.&lt;/p&gt;
&lt;p&gt;&lt;font face="Tahoma" color="#000080"&gt;&lt;strong&gt;What I have completed&lt;/strong&gt;&lt;/font&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;consolidating logs and alerts of network appliances, routers, (managed) switches, firewalls.&lt;br /&gt;This means I have to collect both syslog messages and SNMP traps.&lt;br /&gt;&lt;br /&gt;To do this I am using WinSyslog from Adiscon as a central location for storing syslog messages and Kiwi Syslog Daemon to collect SNMP Traps. From Kiwi SNMP traps are translated into syslog and be poured in the syslog storage.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;consolidating Event log entries from Windows Machines.&lt;br /&gt;For this I am using NTSyslog I got from SourceForge. I am still in a half way as it cannot handle multi-byte languages properly, especially around  &lt;cr&gt;&lt;lf&gt;(what do you say in English? We say this "kaigyo code" in Japanese) and Chinese characters.&lt;br /&gt;&lt;br /&gt;Another point here is the future possibilities of using of &lt;a href="http://www.logparser.com/" target="_blank"&gt;Log Parser&lt;/a&gt;, which is written by a guy in Microsoft. &lt;br /&gt;We can handle eventlog messages in multi-byte languages without a fear with the current versions of the tools released, as it handles those characters as Unicode. &lt;br /&gt;We engineers in regions with multi-byte languages welcome this tool very much as we do not have to think about "how to localize this cozy tool?", etc, etc.&lt;br /&gt;&lt;br /&gt;I am not yet planning utilizing this very kewl and cozy tool in my framework because I want to design "effortless and yet cohered" design, though. &lt;br /&gt;I emphasize here that I am planning to improve/change the whole design so there is such a high possibility that I will be using this tool. &lt;br /&gt;&lt;br /&gt;In the MVP Summit 2004 some of us Japanese MVPs had a chance to discuss on the tool with the author, in which we have heard there will be much improvements in severals of the coming versions. I promise he is so dedicated and is so enthusiastic. ;-)&lt;br /&gt;
&lt;li&gt;Choosing the base platform.&lt;br /&gt;I chose the following stuffs for this system:&lt;br /&gt;&lt;strong&gt;&lt;font color="#006400"&gt;A. Log consolidation&lt;/font&gt;&lt;br /&gt;&lt;/strong&gt;Windows 2000 Server/Server 2003&lt;br /&gt;IIS 5.0 and later&lt;br /&gt;Active Server Pages&lt;br /&gt;Microsoft SQL Server 2000&lt;br /&gt;Adiscon WinSyslog 4.2 or later&lt;br /&gt;Kiwi Syslog Daemon (to just translate SNMP Traps into syslog messages, without an effort.)&lt;br /&gt;Softether (as providing the VPN way to collect logs of servers in several segments of different locations on the Internet.)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;font color="#006400"&gt;B. MRTG and some other system monitors&lt;/font&gt;&lt;/strong&gt;&lt;br /&gt;For this I am using several up to now, and I am planning to consolidate the monitors in just a few nodes, as I want to include links for the graphs of MRTG in the system A. above. I intentionally have several nodes, as in such a way I can troubleshoot more precisely where the bottle neck/system down occurs.&lt;/li&gt;&lt;/lf&gt;&lt;/cr&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Tahoma" color="#000080"&gt;What I am not yet doing&lt;/font&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Consolidating logs scattered around the system and messages written in other forms&lt;br /&gt;As for these logs I am imagining api.log, setup.log, and so on which are written in the text format and scattered around the whole system for Windows OSes. 
&lt;/li&gt;&lt;li&gt;Consolidating Backup and Task Scheduling logs of Windows NT-Based OSes 
&lt;/li&gt;&lt;li&gt;Consolidating HFNETCHK/MBSA resultant texts. 
&lt;/li&gt;&lt;li&gt;Consolidating MRTG results 
&lt;/li&gt;&lt;li&gt;Consolidating results from tools for penetration testings like NIKTO, Syhunt, N-Stealth, Nessus, and so on. 
&lt;/li&gt;&lt;li&gt;Merging and consolidating /var/log/messages and so on in Unix platforms including FreeBSD and Linux. 
&lt;/li&gt;&lt;li&gt;Merging the logs of crond and the texts of logwatch from Unix platforms. 
&lt;/li&gt;&lt;li&gt;Consolidating results of system monitoring softwares like those released from Dell, HP, and so on. 
&lt;/li&gt;&lt;li&gt;Visualize the results to make it easier to confirm what is going on. 
&lt;/li&gt;&lt;li&gt;Issuing alerts via e-mail and web monitor pages. 
&lt;/li&gt;&lt;li&gt;The site design as a whole. (I am using IIS as a web server to show the results.) 
&lt;/li&gt;&lt;li&gt;Designing a fault-tolerant system for both SoftEther and the server.&lt;/li&gt;&lt;/ol&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6082" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Security tips" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx" /><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>KB:314470 Definition of System Partition and Boot Partition</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/05/08/6076.aspx" /><id>/blogs/yamaken/archive/2004/05/08/6076.aspx</id><published>2004-05-09T02:49:00Z</published><updated>2004-05-09T02:49:00Z</updated><content type="html">&lt;p&gt;Sometime it is so confusing, you know. ;-)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/?id=314470" target="_blank"&gt;314470 Definition of System Partition and Boot Partition&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6076" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>SNMP and WMI on Windows: WMIex.MSFT.NET</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx" /><id>/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx</id><published>2004-04-14T04:00:00Z</published><updated>2004-04-14T04:00:00Z</updated><content type="html">&lt;p&gt;The famous &lt;a href="http://snmpboy.msft.net/" target="_blank"&gt;snmpboy site&lt;/a&gt; has evolved dramatically to handle WMI implementation!&lt;/p&gt;
&lt;p&gt;&lt;a href="http://wmiex.msft.net/" target="_blank"&gt;http://wmiex.msft.net/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=4943" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Network Technologies" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx" /><category term="Interoperability" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /></entry><entry><title>KB: 810639 FIX: FTP Passive Mode Support for Firewall Scenarios</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/02/10/kb-810639-fix-ftp-passive-mode-support-for-firewall-scenarios.aspx" /><id>/blogs/yamaken/archive/2004/02/10/kb-810639-fix-ftp-passive-mode-support-for-firewall-scenarios.aspx</id><published>2004-02-10T00:06:00Z</published><updated>2004-02-10T00:06:00Z</updated><content type="html">&lt;p&gt;This article&amp;nbsp;describes how to put controll&amp;nbsp;on&amp;nbsp;the ports used with FTP PASSIVE mode with IIS 5.0.&lt;br /&gt;SP4 is required to enable this.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=810639"&gt;http://support.microsoft.com/?kbid=810639&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2646" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Security tips" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>Tool: Pagedefrag de Sysinternals</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/02/10/tool-pagedefrag-de-sysinternals.aspx" /><id>/blogs/yamaken/archive/2004/02/10/tool-pagedefrag-de-sysinternals.aspx</id><published>2004-02-09T18:42:00Z</published><updated>2004-02-09T18:42:00Z</updated><content type="html">&lt;p&gt;Un utilitaire pour les dossiers defragment qui ne sont pas faits après bootup.&lt;br /&gt;&lt;a href="http://www.sysinternals.com/ntw2k/freeware/pagedefrag.shtml"&gt;http://www.sysinternals.com/ntw2k/freeware/pagedefrag.shtml&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2627" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Misc" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx" /><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /></entry><entry><title>Ev2T</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/01/29/2195.aspx" /><id>/blogs/yamaken/archive/2004/01/29/2195.aspx</id><published>2004-01-30T05:45:00Z</published><updated>2004-01-30T05:45:00Z</updated><content type="html">&lt;p&gt;It is a tool which converts event log messages to SNMP traps.&lt;br /&gt;&lt;a href="http://www.ncomtech.com/download.htm"&gt;http://www.ncomtech.com/download.htm&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;As for multilbyte languages it may not be ready...&lt;br /&gt;At least sending traps to Kiwi has been terrible when I used this tool with Japanese version of Windows Server 2003.&lt;br /&gt;You may have to obtain a management app which is capable of handling multibyte messages like Japanese, Chinese, and Korean.&lt;br /&gt;Anyway there seems no probs when used with English version of NT Kernel-based OSes.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2195" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry><entry><title>Syslog management on Windows platforms.</title><link rel="alternate" type="text/html" href="/blogs/yamaken/archive/2004/01/29/2193.aspx" /><id>/blogs/yamaken/archive/2004/01/29/2193.aspx</id><published>2004-01-30T05:18:00Z</published><updated>2004-01-30T05:18:00Z</updated><content type="html">&lt;p&gt;
Do you know &lt;a href="http://www.winsyslog.com/"&gt;WinSyslog&lt;/a&gt; from &lt;a href="http://www.adiscon.com/"&gt;Adiscon&lt;/a&gt;? It is so cool a tool for us system operators/administrators.&lt;br /&gt;
Check it out at: &lt;a href="http://www.adiscon.com/"&gt;http://www.adiscon.com/&lt;/a&gt;&lt;br /&gt;
(For Japanese: &lt;a href="http://adiscon.port139.co.jp/"&gt;http://adiscon.port139.co.jp/&lt;/a&gt;)&lt;br /&gt;
This tool is so cool, as it allows you to consolidate all the standard error/log messages to one server. With MSSQL you can even display the messages via IIS 4/5. Merging Syslog, SNMP, and Windows Event logs are critical for system admins, to whom we can say this tool is the very solution for managing system health in general. &lt;br /&gt;
You can merge SNMP with syslog, using either the latest version of WinSyslog, or with Kiwi Syslog Daemon (&lt;a href="http://www.kiwisyslog.com"&gt;http://www.kiwisyslog.com&lt;/a&gt;).&lt;br /&gt;

You can merge Windows event logs with the following tools:&lt;br /&gt;
&lt;/p&gt;&lt;blockquote&gt;
&lt;p align="left"&gt;1. Event Reporter from Adiscon&lt;/p&gt;
&lt;p align="left"&gt;2. Event logs to syslog utility from Purdue University.&lt;/p&gt;
&lt;p align="left"&gt;3. ntsyslog service tool from SourceForge&lt;/p&gt;
&lt;p align="left"&gt;cf. I found a localised version of ntsyslog in Vector or Mado-no-mori, which uses EUC-JP for Japanese. If you have already deployed Linux- or *NIX-based solution for the consolidation of logs, this client is just-fit, it seems.&lt;/p&gt;&lt;/blockquote&gt;
Note: there are other tools in the world to facilitate this function. According to Kawabata-san (&lt;a href="http://www.kawabata.com/"&gt;http://www.kawabata.com/&lt;/a&gt;), you can even write up the tool that just-fits to your need. ;-)&lt;br /&gt;
&lt;p&gt;***System Requirements:&lt;/p&gt;
A. System: See the URLs above&lt;br /&gt;
B. Human:&lt;br /&gt;
&lt;blockquote dir="ltr" style="MARGIN-RIGHT: 0px"&gt;
&lt;p align="left"&gt;B-1. Knowledge of syslog (unix and network devices you use.)&lt;/p&gt;
&lt;p align="left"&gt;B-2. Ability or Experience of manually parsing eventlogs on Windows&lt;/p&gt;
&lt;p align="left"&gt;B-3. Ability to configure network devices to emit logs, if you think you'd like to add the target of monitoring.&lt;/p&gt;
&lt;p align="left"&gt;B-4. Ability to configure SNMP on servers and clients to enable them to emit SNMP messages.&lt;/p&gt;
&lt;p align="left"&gt;B-5. Ability/experience to configure server management tools like Allied Telesyn SwimView, HP OpenView or Dell Server Administrator /IT assistant for PowerEdge Systems.&lt;/p&gt;
(It is okay to use other administrative tools according to the needs at your managed networks. Tools above are just as examples.)&lt;br /&gt;&lt;/blockquote&gt;
Outputs are just like &lt;a href="http://www.geocities.jp/lg_de_sucre/cisco/softether/"&gt;this&lt;/a&gt;.(Special thanks to lg_de_sucre, a cool guy working together.)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;Howto: Manage logs (delete unwanted/needless log messages)?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Create jobs (using T-SQL) from SQL Server Enterprise Manager.&lt;br /&gt;
&lt;br /&gt;Howto: merge the route and simplify the system?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Use SoftEther or other VPN products.&lt;br /&gt;
&lt;br /&gt;Howto: merge outputs of Snort?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Consult with docs around Snort.&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://www.winsnort.com/"&gt;http://www.winsnort.com/&lt;/a&gt; or &lt;a href="http://www.snort.org/"&gt;http://www.snort.org/&lt;/a&gt; are both good-starts.&lt;br /&gt;
&lt;br /&gt;Ah, it seems I am gonna miss the last train, so see ya later!&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
YamaKen at the office in Tokyo.&lt;br /&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2193" width="1" height="1"&gt;</content><author><name>kenji</name><uri>http://msmvps.com/members/kenji/default.aspx</uri></author><category term="Network Technologies" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx" /><category term="Tools" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx" /><category term="Interoperability" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx" /><category term="Windows management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx" /><category term="Server management" scheme="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx" /></entry></feed>