<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>システム管理な雑記 -- Sleeve notes of a sysadmin -- : Windows management</title><link>http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx</link><description>Tags: Windows management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Note: Migrating existing user profiles to new accounts on Windows machines (XP/2003)</title><link>http://msmvps.com/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx</link><pubDate>Mon, 08 Oct 2007 05:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1239557</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=1239557</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx#comments</comments><description>-- English -- Moving user profiles, which is needed during/after migration from existing environments to Active Directory, is a kind of somewhat tough thing, I mean the amounts of target accounts and time consumed, and some of caveats. Currently we can...(&lt;a href="http://msmvps.com/blogs/yamaken/archive/2007/10/07/note-migrating-existing-user-profiles-to-new-accounts-on-windows-machines-xp-2003-vista.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1239557" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>Honeynet Security Console</title><link>http://msmvps.com/blogs/yamaken/archive/2004/05/16/6546.aspx</link><pubDate>Sun, 16 May 2004 23:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6546</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=6546</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/05/16/6546.aspx#comments</comments><description>&lt;p&gt;From &lt;a title="seculogger" href="http://www.7th-angel.net/seculog/" target="_blank"&gt;seculogger&lt;/a&gt;'s &lt;a href="http://www.7th-angel.net/seculog/item/548.html" target="_blank"&gt;blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.activeworx.org/programs/hsc/index.htm"&gt;Honeynet Security Console&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It seems very neat. I decided that I should evaluate this, with &lt;a href="http://project.honeynet.org/tools/sebek/" target="_blank"&gt;sebek!&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6546" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx">Misc</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx">Security tips</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002</title><link>http://msmvps.com/blogs/yamaken/archive/2004/05/10/6148.aspx</link><pubDate>Mon, 10 May 2004 15:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6148</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=6148</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/05/10/6148.aspx#comments</comments><description>&lt;p&gt;This webcast covers topics around "how to use the recovery console" and more about troubleshooting the boot phase. It is a must thing, you know, as we engineers handle issues around servers. ;-)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=/servicedesks/webcasts/en/wc062502/wct062502.asp" target="_blank"&gt;Microsoft Support Webcast: Microsoft Windows XP: Exploring Boot Options and Recovery Console June 25, 2002&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6148" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx">Security tips</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item><item><title>KB:314470 Definition of System Partition and Boot Partition</title><link>http://msmvps.com/blogs/yamaken/archive/2004/05/08/6076.aspx</link><pubDate>Sun, 09 May 2004 02:49:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6076</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=6076</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/05/08/6076.aspx#comments</comments><description>&lt;p&gt;Sometime it is so confusing, you know. ;-)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/?id=314470" target="_blank"&gt;314470 Definition of System Partition and Boot Partition&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6076" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item><item><title>SNMP and WMI on Windows: WMIex.MSFT.NET</title><link>http://msmvps.com/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx</link><pubDate>Wed, 14 Apr 2004 04:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:4943</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=4943</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx#comments</comments><description>&lt;p&gt;The famous &lt;a href="http://snmpboy.msft.net/" target="_blank"&gt;snmpboy site&lt;/a&gt; has evolved dramatically to handle WMI implementation!&lt;/p&gt;
&lt;p&gt;&lt;a href="http://wmiex.msft.net/" target="_blank"&gt;http://wmiex.msft.net/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=4943" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx">Network Technologies</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>KB: 810639 FIX: FTP Passive Mode Support for Firewall Scenarios</title><link>http://msmvps.com/blogs/yamaken/archive/2004/02/10/kb-810639-fix-ftp-passive-mode-support-for-firewall-scenarios.aspx</link><pubDate>Tue, 10 Feb 2004 00:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:2646</guid><dc:creator>kenji</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=2646</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/02/10/kb-810639-fix-ftp-passive-mode-support-for-firewall-scenarios.aspx#comments</comments><description>&lt;p&gt;This article&amp;nbsp;describes how to put controll&amp;nbsp;on&amp;nbsp;the ports used with FTP PASSIVE mode with IIS 5.0.&lt;br /&gt;SP4 is required to enable this.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=810639"&gt;http://support.microsoft.com/?kbid=810639&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2646" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx">Security tips</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item><item><title>Tool: Pagedefrag de Sysinternals</title><link>http://msmvps.com/blogs/yamaken/archive/2004/02/10/tool-pagedefrag-de-sysinternals.aspx</link><pubDate>Mon, 09 Feb 2004 18:42:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:2627</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=2627</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/02/10/tool-pagedefrag-de-sysinternals.aspx#comments</comments><description>&lt;p&gt;Un utilitaire pour les dossiers defragment qui ne sont pas faits après bootup.&lt;br /&gt;&lt;a href="http://www.sysinternals.com/ntw2k/freeware/pagedefrag.shtml"&gt;http://www.sysinternals.com/ntw2k/freeware/pagedefrag.shtml&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2627" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx">Misc</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>Ev2T</title><link>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2195.aspx</link><pubDate>Fri, 30 Jan 2004 05:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:2195</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=2195</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2195.aspx#comments</comments><description>&lt;p&gt;It is a tool which converts event log messages to SNMP traps.&lt;br /&gt;&lt;a href="http://www.ncomtech.com/download.htm"&gt;http://www.ncomtech.com/download.htm&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;As for multilbyte languages it may not be ready...&lt;br /&gt;At least sending traps to Kiwi has been terrible when I used this tool with Japanese version of Windows Server 2003.&lt;br /&gt;You may have to obtain a management app which is capable of handling multibyte messages like Japanese, Chinese, and Korean.&lt;br /&gt;Anyway there seems no probs when used with English version of NT Kernel-based OSes.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2195" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item><item><title>Syslog management on Windows platforms.</title><link>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2193.aspx</link><pubDate>Fri, 30 Jan 2004 05:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:2193</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=2193</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2193.aspx#comments</comments><description>&lt;p&gt;
Do you know &lt;a href="http://www.winsyslog.com/"&gt;WinSyslog&lt;/a&gt; from &lt;a href="http://www.adiscon.com/"&gt;Adiscon&lt;/a&gt;? It is so cool a tool for us system operators/administrators.&lt;br /&gt;
Check it out at: &lt;a href="http://www.adiscon.com/"&gt;http://www.adiscon.com/&lt;/a&gt;&lt;br /&gt;
(For Japanese: &lt;a href="http://adiscon.port139.co.jp/"&gt;http://adiscon.port139.co.jp/&lt;/a&gt;)&lt;br /&gt;
This tool is so cool, as it allows you to consolidate all the standard error/log messages to one server. With MSSQL you can even display the messages via IIS 4/5. Merging Syslog, SNMP, and Windows Event logs are critical for system admins, to whom we can say this tool is the very solution for managing system health in general. &lt;br /&gt;
You can merge SNMP with syslog, using either the latest version of WinSyslog, or with Kiwi Syslog Daemon (&lt;a href="http://www.kiwisyslog.com"&gt;http://www.kiwisyslog.com&lt;/a&gt;).&lt;br /&gt;

You can merge Windows event logs with the following tools:&lt;br /&gt;
&lt;/p&gt;&lt;blockquote&gt;
&lt;p align="left"&gt;1. Event Reporter from Adiscon&lt;/p&gt;
&lt;p align="left"&gt;2. Event logs to syslog utility from Purdue University.&lt;/p&gt;
&lt;p align="left"&gt;3. ntsyslog service tool from SourceForge&lt;/p&gt;
&lt;p align="left"&gt;cf. I found a localised version of ntsyslog in Vector or Mado-no-mori, which uses EUC-JP for Japanese. If you have already deployed Linux- or *NIX-based solution for the consolidation of logs, this client is just-fit, it seems.&lt;/p&gt;&lt;/blockquote&gt;
Note: there are other tools in the world to facilitate this function. According to Kawabata-san (&lt;a href="http://www.kawabata.com/"&gt;http://www.kawabata.com/&lt;/a&gt;), you can even write up the tool that just-fits to your need. ;-)&lt;br /&gt;
&lt;p&gt;***System Requirements:&lt;/p&gt;
A. System: See the URLs above&lt;br /&gt;
B. Human:&lt;br /&gt;
&lt;blockquote dir="ltr" style="MARGIN-RIGHT: 0px"&gt;
&lt;p align="left"&gt;B-1. Knowledge of syslog (unix and network devices you use.)&lt;/p&gt;
&lt;p align="left"&gt;B-2. Ability or Experience of manually parsing eventlogs on Windows&lt;/p&gt;
&lt;p align="left"&gt;B-3. Ability to configure network devices to emit logs, if you think you'd like to add the target of monitoring.&lt;/p&gt;
&lt;p align="left"&gt;B-4. Ability to configure SNMP on servers and clients to enable them to emit SNMP messages.&lt;/p&gt;
&lt;p align="left"&gt;B-5. Ability/experience to configure server management tools like Allied Telesyn SwimView, HP OpenView or Dell Server Administrator /IT assistant for PowerEdge Systems.&lt;/p&gt;
(It is okay to use other administrative tools according to the needs at your managed networks. Tools above are just as examples.)&lt;br /&gt;&lt;/blockquote&gt;
Outputs are just like &lt;a href="http://www.geocities.jp/lg_de_sucre/cisco/softether/"&gt;this&lt;/a&gt;.(Special thanks to lg_de_sucre, a cool guy working together.)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;Howto: Manage logs (delete unwanted/needless log messages)?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Create jobs (using T-SQL) from SQL Server Enterprise Manager.&lt;br /&gt;
&lt;br /&gt;Howto: merge the route and simplify the system?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Use SoftEther or other VPN products.&lt;br /&gt;
&lt;br /&gt;Howto: merge outputs of Snort?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Consult with docs around Snort.&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://www.winsnort.com/"&gt;http://www.winsnort.com/&lt;/a&gt; or &lt;a href="http://www.snort.org/"&gt;http://www.snort.org/&lt;/a&gt; are both good-starts.&lt;br /&gt;
&lt;br /&gt;Ah, it seems I am gonna miss the last train, so see ya later!&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
YamaKen at the office in Tokyo.&lt;br /&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2193" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx">Network Technologies</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item></channel></rss>