Windows Server 2008 Event Log Archiver Help/Suggestions RRS feed

  • Question

  • Here is a batch file I wrote using WinRM and WEVTUTIL to clear and back-up event logs to our file server. Also includes a case statment to select the appropriate folder based on the given month. Just wanted to share, cause from all the research I did, I couldn't find anything like this that was complete. Also, can anyone think of a way to shorten this up a bit? Or possibly a better method?

    As a after thought, also have set this up as a Scheduled Task after removing the PAUSE command from the script and /q :) Thanks for any input!

    :::        LOG ARCHIVER		                   :::
    :::        GAGE HURST                              :::
    :::        13 SEPTEMBER, 2012                      :::
    ::Get the current date and save it to the %date% variable::
    FOR /F "TOKENS=2-4 DELIMS=/ " %%A IN ('DATE /T') DO (SET date=%%A%%B%%C)
    ::Creates the "Month" variable which changes value based on the actual month, and thus sets the"Folder" variable to correspond to the correct folder 
    ::located on the file server.
    FOR /F "TOKENS=2-4 DELIMS=/ " %%A IN ('DATE /T') DO (SET Month=%%A)
    GOTO CASE_%Month%
    	IF %Month%==01 SET Folder=1-January
    	IF %Month%==02 SET Folder=2-February
    	IF %Month%==03 SET Folder=3-March
    	IF %Month%==04 SET Folder=4-April
    	IF %Month%==05 SET Folder=5-May
    	IF %Month%==06 SET Folder=6-June
    	IF %Month%==07 SET Folder=7-July
    	IF %Month%==08 SET Folder=8-August
    	IF %Month%==09 SET Folder=9-September
    	IF %Month%==10 SET Folder=10-October
    	IF %Month%==11 SET Folder=11-November
    	IF %Month%==12 SET Folder=12-December
    ::Pulls machine names from .txt file you created, clears them, and back's them up to the designated remote machine::
    FOR /F "TOKENS=1,2* delims= " %%X IN (C:\servers.txt) DO ECHO %%X 
    FOR /F "TOKENS=1,2* delims= " %%X IN (C:\servers.txt) 
    DO WEVTUTIL CL Application /BU:"\\remote_machine\f$\2012\%Folder%\%%X-%date%-APP.evtx"
    FOR /F "TOKENS=1,2* delims= " %%X IN (C:\servers.txt) DO WEVTUTIL CL Security /BU:"\\remote_machine\f$\2012\%Folder%\%%X-%date%-SEC.evtx" 
    FOR /F "TOKENS=1,2* delims= " %%X IN (C:\servers.txt) DO WEVTUTIL CL System /BU:"\\remote_machine\f$\%%X-%date%-SYS.evtx" 

    Friday, September 14, 2012 7:24 AM