Showing posts with label Windows 7. Show all posts
Showing posts with label Windows 7. Show all posts

Tuesday, October 4, 2011

How To: Use Windows Event Collector

Many of my students have been unsure how to use a new feature of Windows 2008 and Windows 7 called the Event collector.  This feature allows one or more computers to forward a copy of events from selected logs, to a different computer that is called an event collector.  For example, assume that I have four servers.  I want to have three of the servers send any critical and error events from their Applications and System logs to one server so that I can review them.  

My assumptions for this article are that all four computers are domain joined.  Only domain joined computers can use this feature.  My other assumptions are that my computers will communicate using HTTP port 5985 and none of my servers are domain controllers.   Below I will outline the steps based upon my assumptions.
1. Decide which computer will be the collector of events and which computer(s) will be forwarding events to the collector.  


      2. Logon to each computer that will forward events as an Administrator and open a command prompt as an Administrator. 
a.  Type winrm quickconfig and press Enter.  WinRM will then ask you about adding a WinRM firewall exception as show below.  This screen shot is from a Windows Server 2008 R2 computer.  (You may be prompted to set the WinRM service to a delayed auto start and setting the WinRM firewall exception.  This is the behavior of Windows 7.)  Accept the change(s).













b. Continue performing this step on all computers that will be sending events.

3. Now you are ready to logon to the collector.  This is the computer that will be collecting the events.
a. Again, type winrm quickconfig and press Enter. 
b. Then type wecutil qc and press Enter.  This will allow users on a different computer to subscribe to (send) events on this computer.
c. When prompted to change the wecutil startup mode, click y and press Enter.
d. Type Exit and press Enter to exit the command prompt.
  

4. Click Start| Administrative Tools |Computer Management. 

5. Expand the Event Viewer and select the Subscriptions node.
        a. Right-click on Subscriptions and select Create Subscription.
        b. In the Subscription Properties page, in the Subscription name field, type a 

            subscription name i.e. Server1 logs.
        c. In the Subscription Type and source computers section, verify that Collector 

            initiated is selected and click Select Computers.
            i. Click Add Domain Computer and type the name of the server and click Check Names.
            ii. Click OK.
            iii. Click Test.
            iv. Read the message. Click OK.
        d. Click Select Events.
            i. In the Logged field, use the drop-down list and select Last 24 hours.
            ii. In the Event level field, select Critical, Error and Warning.
            iii. Select By Log.  Using the drop-down list expand Windows Logs and 

                select Application and System logs.
            iv. Click OK.

          



        e. Click Advanced.
            i. Verify that the Machine Account is selected.
            ii. Examine the port.  (Remember the firewall will need to allow traffic from this port.)
            iii. Click OK.
        f. Click OK to close the Subscription Properties screen.


6. Your next task is to add the collector computer’s account to each of the local Administrator’s groups.  (If you are using a domain controller, you will need to set up a user account that has permissions to read the event logs.)


7. Once that task is finished, expand the Event Viewer\Windows Logs\Forwarded Events.


8. This is the location that your logs from the other servers will send a copy of their Critical and Errors that are displayed in their System and Application logs.


- Janet Nichols, Windows Server Expert; MCT, MCSE, MCITP: Enterprise Admin, Server Admin; Windows 7 EDA, MCTS LinkIn with Janet

Bookmark and Share

Tuesday, July 5, 2011

Using the Resource Monitor in Windows Server 2008 R2

Students in one of my recent Windows Server 2008 R2 classes, were asking me how to discover what is in SvcHost.exe, as well as what services and ports are in use by any of the running process. I suggested that they take a look at the Resource Monitor. 

To discover what is running in any of the instances of the SvcHost.exe, first launch the Resource Monitor. To launch the Resource Monitor click the Start button and type Resource and select the Resource Monitor. Then click on the CPU tab, as demonstrated below:

In the Processes list, locate a SvcHost.exe.   (It is easiest to click on the Image heading to sort the list alphabetically. )  Select the checkbox to the left of the SvcHost.exe.  This will move the selected SvcHost.exe to the top of the Image list, as demonstrated below:
Now that the SvcHost.exe is selected, expand the Services portion of the window, to reveal the Services running in this SvcHost.exe. 
To view the files that the SvcHost.exe is utilizing, expand the Associated Modules section.
To view the ports that the SvcHost.exe is using select the Network tab, and expand the Listening ports section.
I think you will find the Resource Monitor a very useful tool, in Windows Server 2008 R2 as well as Windows 7.



- Janet Nichols, Windows Server Expert; MCT, MCSE, MCITP: Enterprise Admin, Server Admin; Windows 7 EDA, MCTS LinkIn with Janet

Bookmark and Share


Monday, May 23, 2011

Blogging: Exchange & Lync

TechEd North America 2011 is over, and I'm back in Leawood completely reinvigorated. One of the things I've decided to pursue is a blog dedicated to Exchange and Lync (Unified Communication). To that end, I've put together a blog for the UC community, and you can find it at http://www.geekswithblogs.net/ucaggregate.


You can also get an idea as to what all of the excitement is about by checking out some of the sessions from the past week here: http://dayngo.com/channel9/Download/15928.

Lots of great content on Exchange & Lync there. The site does require Silverlight.


- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Thursday, May 5, 2011

New Windows 7 and Windows Azure Course Offerings

Centriq Training is pleased to announce it will offer two new courses from Microsoft in July of 2011.

Troubleshooting and Supporting Windows 7 in the Enterprise (MS-6293)
This three-day instructor-led course will teach IT Professionals, experienced with Microsoft Windows XP and Windows Vista in a Tier 2 support environment, how to support the operating system and solve technical troubleshooting problems in a Windows 7 and Windows Server 2008 R2 networking environment. This course also directly supports the EDST exam. Upcoming dates: July 25-July 27

Windows Azure Solutions with Microsoft Visual Studio 2010 (MS-50466)
Centriq will be the first company in the area to offer this new Windows Azure course! This class is an introduction to cloud computing and specifically Microsoft's public cloud offering in Windows Azure. Windows Azure has been described by Microsoft as an operating system for "the cloud". In this class, students explore this new cloud operating system and learn how to write, deploy and monitor .NET applications in Azure. Upcoming dates: July 20-July 22

For more information or to save your seat in these upcoming classes, visit http://www.centriq.com/ or call your Account Executive at 913-322-7000.


- Justin Ruby, Corporate Sales Manager LinkIn with Justin

Bookmark and Share

Monday, April 4, 2011

50 best tips for Windows 7

I do love compilation articles that list a number of great tips that anybody can skim through and find some nugget that can be useful. To that end, here's a link to a pretty decent article that lists some of the 50 best tips for Windows 7.




- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Tuesday, March 29, 2011

Windows Thin PC Preview!


Microsoft has released a community technology preview (CTP) of its Windows Thin PC product.
 
Windows Thin PC (WinTPC) is a new version of Windows 7 designed specifically for Virtual Desktop Infrastructure (VDI) customers. Windows Thin PC is a smaller footprint, locked down version of Windows 7 designed for virtualized environments to rebuild their existing PCs as thin clients. PCs with WinTPC will not require the VDA license that regular thin clients will need to access VDI desktops according to Microsoft.
 
http://www.winrumors.com/windows-thin-pc-beta-download-now-available/

- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Monday, February 28, 2011

Windows 7 (and Windows Server 2008 R2) Service Pack 1

OK, folks, back up your systems, and get ready for the update! I would recommend doing an image backup (Start/Control Panel/System and Security/Backup and Restore/Create a System Image) before deploying the SP1 for Windows 7, regardless of the version. You can get the Technet information here: (http://technet.microsoft.com/en-us/library/ff817622(WS.10).aspx), and an easier to read summary on the service pack here: (http://www.eweek.com/c/a/Windows/Microsoft-Polishes-Desktop-OS-101452/).


- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Monday, February 7, 2011

Recommendation: CODE Magazine

I recently got a renewal to CODE Magazine.  This great magazine has really good articles for developers, and the source code in the magazine is color-coded, just like it is in the Visual Studio editors.  They also have sample code available on their website that you can copy for projects as well.

In the most recent issue, Jan/Feb 2011, they have an interesting article by the publisher of the magazine, Markus Egger. The story covers the Windows Presentation Foundation (WPF) and Silverlight ListBox. In the article, Markus shows that by using styles and templates you can turn that ListBox into almost any representation of multiple items that you can imagine. It is really fascinating and something I think that every WPF/Silverlight developer should know. In fact, if you are still doing Windows Forms, and really needed convincing that it was time to switch to WPF, this should do it. 

Another recommended article for reference is Getting Started with Windows Phone 7 Development


- Leslie Koorhan, .NET Expert;
MCT, MCSD (.NET), MCTS, MCDBA, MCPD LinkIn with Leslie

Bookmark and Share

Wednesday, January 26, 2011

Resize picture attachments using Windows 7 or Outlook

Manage Picture Attachments using Microsoft Outlook

If you email photos using Microsoft Outlook, you might like a quick and easy way to "shrink" the file size.


In Outlook 2007, after you attach a photo, click the Insert tab on the ribbon, and then click the dialog box launcher in the bottom right corner of the Include tool group. The Attachment Options task pane will open on the right side of the message window.


Notice the Picture Options area in the bottom half of the pane: click the drop down arrow and choose to resize your picture to Small, Medium, or Large size. You might want to click the check box at the bottom of the pane to automatically "Show when attaching files."


In Outlook 2010, this feature has been changed. To downsize a picture attachment in 2010, after you have attached the picture, click the File tab to access the backstage view of the message window. In the Info category, choose the option at the top to "Resize large images when I send this message." Images will be a reduced to a maximum of 1024x768 pixels, which must be done on a per-message basis. Click the File tab again to return to the message window.



A third option exists for Windows 7 users. Select one or more picture files in an Explorer window. Right click on a file name and choose Send to/ Mail recipient from the menu. The Attach Files dialog box will appear. Choose Smaller, Small, Medium (the 1024x768 default), Large, or Original Size. Click the Attach button and a new message will be created with the images attached and sized as you have selected.




- Irene Heckert, Microsoft Office Expert;
CTT, MCAS, ITIL Certified, MOS LinkIn with Irene

Bookmark and Share

Security Tip for Windows Users

Hey, Windows Users! Thought this article was important enough to pass along, especially if you are dead set on closing all of your vulnerabilities:

http://www.zdnet.com/blog/bott/the-one-security-tool-every-windows-user-should-know-about/2848

Good luck!


- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Tuesday, January 18, 2011

Get a jump on your files: Windows 7 jump lists






In Windows 7, jump lists are a list of the files you have opened recently from an application. These appear on the Start menu when you point at the application. Click on the file name and the file will open.

But wait... there's more! If you have a file you want to have quick access to, "pin" it to the list. Slide your mouse over the file name, and then click on the pushpin you see to the right of the name. The file will now appear at the top of the recent list. If you need to remove a file name from the list, just click the push pin again to "un-pin" it.


- Irene Heckert, Microsoft Office Expert;
CTT, MCAS, ITIL Certified, MOS LinkIn with Irene

Bookmark and Share

Monday, January 10, 2011

Windows 7 Administration: Create your own toolbox!

I recently spent a couple of days on-site teaching a group of admins some of the ins-and-outs of Windows 7, and one of my students commented that it would be nice to have all of the tools available in one spot, instead of having to look in the Control Panel for this tool, dig into Computer Management for this other one, etc. 

After doing a little bit of a search, I think I found the solution she was looking for and shared it with her and the rest of the admins, and it seems appropriate to share it with everyone else as well.

Here's the trick - create a folder in explorer, and give it a name. The example I found use the name "Everything", but you can name it whatever you like, "Command Center", "Master Links", it doesn't really matter, as long as it makes sense to you. I'm going to stick with the "Everything" example. After you've created it, go to rename the folder and append this string to the name "{ED7BA470-8E54-465E-825C-99712043E01C}", so the full name becomes "Everything.{ED7BA470-8E54-465E-825C-99712043E01C}" (Don't forget the period between the name of the folder and the extension). 

After you have done that, you'll notice a change in the icon for the folder and when you open it up, you'll have links to just about everything you'll ever need to administer Windows 7.

Thanks to techrader.com for this tip - here's the link to this tip, and many others!

- Bob Reinsch, Microsoft Exchange/Windows 7 Expert; MCT, MCITP LinkIn with Bob

Bookmark and Share

Thursday, January 6, 2011

Installing RSAT on Windows 7 Professional, Enterprise or Ultimate Machine

A common question that I am receiving from students in many classes is how to install the Remote Server Administration Tools (RSAT) on a Windows 7 Professional, Enterprise or Ultimate computer. The first task is to download the Remote Server Administration Tools for Windows 7. 

To find the tools click here. Once on the website, select either the 32 or 64-bit RSAT and click download. Once the tools are downloaded, log on to the Windows 7 computer as a member of the Administrators group. 

1. Double-click the package to unpack it. When prompted to install the KB click Yes. 
2. Read and accept the License agreement. 
3. Wait for the installation to complete. Once the installation of the RSAT is complete, continue to the next step.
4. Click Start, select Control Panel, and then select Programs.
5. In the Programs and Features area, select Turn Windows features on or off. If prompted by User Account Control, click Continue.





6. In the Windows Features dialog box, expand Remote Server Administration Tools. Expand the selections and choose the remote management tools that you wish to install. Once you have completed your selections, click OK.





7. The Start menu should now have display the Administration Tools. If not, follow the next steps to add it.
  • A) Right-click the Start menu and select Properties.
  • B) On the Start menu tab, click Customize.
  • C) In the Customize Start Menu dialog box, scroll down to the System   Administrative Tools and select Display on All Programs menu and the Start menu.
  • D) Click OK.

- Janet Nichols, Windows Server Expert; MCT, MCSE, MCITP: Enterprise Admin, Server Admin; Windows 7 EDA, MCTS LinkIn with Janet

Bookmark and Share