Readme File Network Event Viewer 2008 Mon, 17 Aug 2009 08:30:23 MDT Copyright (c) 2002-2009 Corner Bowl Software Corporation. All Rights Reserved. This document provides late-breaking or other information that supplements the software documentation. --------------------------------------------------------------------------- Build Notes --------------------------------------------------------------------------- --------------------------------------------------------------------------- Build 8.0.0.77 - Mon, 17 Aug 2009 08:11:11 MDT --------------------------------------------------------------------------- In previous builds the Syslog Configuration Wizard did not display the maximum consolidation log file size value when modified by the user. This bug has been fixed. In previous builds the filters combo box was enabled when viewing a frequency detection report even through changing the filter did nothing. The combo box is now disabled when viewing a frequency detection report. In previous builds when converting a simple filter to a complex filter the description was now included in the conversion. --------------------------------------------------------------------------- Build 8.0.0.76 - Mon, 18 May 2009 03:02:21 MDT --------------------------------------------------------------------------- In previous builds the service was incorrectly reading and writing the SQL Server Windows Authentication Mode flag to the hkey_current_user registry key. The service now reads the hkey_local_machine registry key. In previous builds the service was reading the hkey_current_user when choosing to display log names using color while firing email alerts. If the service account did not have access to the current user registry the service would error when firing these alerts. If this error is thrown, the service now defaults to show the logs using color and continues without incident. --------------------------------------------------------------------------- Build 8.0.0.75 - Tue, 05 May 2009 04:44:33 MDT --------------------------------------------------------------------------- When impersonating to Windows 2000 computers users may have received an invalid logon failure. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.74 - Mon, 06 Apr 2009 10:23:38 MDT --------------------------------------------------------------------------- In previous builds the logical group assignment did not work when configuring a single computer. This bug has been resolved. We upgraded the 3rd party toolbar, docking bar, and menu bar controls to the vendors latest version. --------------------------------------------------------------------------- Build 8.0.0.73 - Tue, 03 Feb 2009 03:49:38 MST --------------------------------------------------------------------------- In previous builds when tabbing through the Logical Group combo-box within the Configuration Wizards the logical groups were removed. This bug has been resolved. In previous builds users could get an error when closing the Event Log Configuration Wizard stating the syslog monitor did not have a filter or action installed. This bug has been resolved. --------------------------------------------------------------------------- Build 8.0.0.72 - Mon, 02 Feb 2009 02:04:41 MST --------------------------------------------------------------------------- In previous builds the Windows authentication mode option was not loaded even though set causing a login failure when attempting to read data from the database. This bug has been resolved. --------------------------------------------------------------------------- Build 8.0.0.71 - Mon, 12 Jan 2009 04:02:00 MST --------------------------------------------------------------------------- In previous builds the export to HTML did not enable users to include the user entered notes to the output. Users can now add the {NOTES} tag to the HTML output enabling the user entered notes to be included in the output. --------------------------------------------------------------------------- Build 8.0.0.70 - Fri, 19 Dec 2008 12:10:48 MST --------------------------------------------------------------------------- When consolidating logs to the file system and creating a report to auxiliary data source logs, the available log files did not display within the Report Wizard. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.69 - Fri, 12 Dec 2008 03:26:43 MST --------------------------------------------------------------------------- In previous builds users were able to show the password used to access remote logs from within the Configuration Wizard. The button has now been removed. The syslog server now includes support for consolidation filters. To set a consolidation filter, select the computer or device of interest, select Syslog Configuration Wizard from the File menu item. From the Options tab specify the consolidation filter. The Syslog Wizard also had the incorrect title on the Actions tab. Lastly, the Syslog Wizard allowed the user to assign an action filter without applying an action. These bugs have been fixed. --------------------------------------------------------------------------- Build 8.0.0.67 - Thu, 04 Dec 2008 03:54:42 MST --------------------------------------------------------------------------- In previous builds the user interface always tailed the service log file which if left open locked the file from being truncated by the service. If the user closes the Service Output window now, the user interface shuts down the tail enabling the service to truncate the log. In previous builds if the auto refresh was turned on and the applied filter did not allow any entries to display a message box would display ever time the auto refresh ran. Unlimitedly 100s of message box would stack on top each other. The message no longer displays. --------------------------------------------------------------------------- Build 8.0.0.66 - Mon, 01 Dec 2008 10:47:36 MST --------------------------------------------------------------------------- In previous builds the truncate now function found within the Options dialog did not apply the latest user specified rules prior to running the truncate function. This bug has been fixed. In previous builds the truncate database table function incorrectly logged the number of entries removed from the primary table. This bug has been fixed. In previous builds when removing the maximum downloaded log size restriction (files system only) the maximum size value would still apply if the user changed the value even when the check box was de-selected. This bug has been fixed. In some cases a report would fail to execute or properties open. This error should have only been seen when a previous major version was installed prior to installing the latest version. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.64 - Thu, 20 Nov 2008 01:18:27 MST --------------------------------------------------------------------------- In previous builds a SQL syntax error was thrown when using MySQL, the archive option was enabled and the computer name contained a dash within the name. The SQL syntax neglected to wrap the table name with single quotes. This bug has been resolved. The Print Current Page function has been modified to allow users the option to override the HTML template. We also added the Print Current Page command to the detail view’s popup menu. The Save Current Page function has been modified to allow users the option to override the HTML template when exporting to HTML. Numerous UI enhancements were made to the Save As and Email Selected Logs/Current View dialogs. We have added a tutorial that teaches users how to print a date range of entries from the event log repository. In previous builds on Windows Vista and Server 2008 when exporting logs users were unable to browse the local disk. This bug has been fixed. When scheduling a report that outputs to a file, users now have the option to backup the previous report prior to running the report. When scheduling a report that outputs to a database table, users now have the option to clear the table prior to running the report. When scheduling a frequency detection report that outputs to a database table or downloading a log that has a frequency detection database table action assigned, the table now includes a column to store the count of messages detected within the time range. If the table was created prior to this build, the table is altered to include the count column. Current records are defaulted to null. In previous builds when firing a message box or tray icon popup alert on behalf of a download that fires actions based on frequency detection rules, the count of entries received that matched the filter criteria was not displayed. This limitation has been resolved. --------------------------------------------------------------------------- Build 8.0.0.61 - Fri, 14 Nov 2008 09:41:35 MST --------------------------------------------------------------------------- In previous builds users could not easily specify the logical operand (AND/OR) to apply to new complex filter criteria groups. This bug has been fixed. In previous builds a non-fatal error was thrown when running a logon failure report when the user only configured an account logon report or the user only configured a logon report but not both. This bug has been fixed. The selection behavior has been altered when viewing the Configured Computers or Downloaded Logs views and selecting the Syslog Configuration Wizard. If a syslog node is selected, the wizard opens with the computer or device the syslog node belongs too. If other nodes are checked, but the currently selected node is not, the checked nodes are not included within the wizard. The tab order within the Create New Filter dialog was incorrect. This bug has been fixed. Per a user’s request fading popup menu items is now a user settable option. To disable the fading popup menu items select Options from the Tools menu item. Select the Display tab. Select None from the ‘Popup animation’ check box. When searching for entries on Windows Vista it was difficult to see the entry that was found. The list view focused color has been alerted to use a lighter shade of the highlighted color. In previous builds the tray icon had a one minute delay built in as a work around for a startup issue rarely seen on Windows Vista. We believe we have resolved the issue and have therefore removed the startup delay. In previous builds the installation did not automatically install the platform dependent .Net 2.0 Framework on I64 and X64 computers that did not already have the prerequisite installed. The installation has been modified to, if necessary, download the prerequisites from Microsoft and install them. --------------------------------------------------------------------------- Build 8.0.0.58 - Sun, 09 Nov 2008 01:24:43 MST --------------------------------------------------------------------------- In previous builds when switching between displayed log views, the message, data, and notes windows did not update properly. This bug has been resolved. We have added an option to the Options dialog to hide the newly displaying filter prompt dialog when viewing an event log. From any of the detail list views, pressing Ctrl-A now selects all items. Several UI enhancements were made to reduce drawing flicker and more appropriately update the mouse cursor. --------------------------------------------------------------------------- Build 8.0.0.57 - Wed, 05 Nov 2008 09:48:26 MST --------------------------------------------------------------------------- Users can now create failed logon reports on-demand or per a configured schedule. In previous builds when pressing the left arrow while viewing a sub-group within a log view an object reference error was thrown. This bug has been fixed. Users can now manually specify a device’s IP address from within the Syslog Configuration Wizard. Users can now map computers from within the Configuration Wizard. Users can now display the Active Directory Auto Configurator via a menu item under the Tools menu item. Users can now create, modify and delete filters from the Consolidation tab within the Configuration Wizard. Fixed a potential temporary file leak when sending HTML formatted emails. In recent builds the configuration template save and load buttons were not visible until after the user resized the Configuration Wizard dialog. The buttons have been moved to a location that is visible when the dialog is at its minimum allowed or default size. --------------------------------------------------------------------------- Build 8.0.0.55 - Thu, 23 Oct 2008 01:15:12 MDT --------------------------------------------------------------------------- When rebooting a Server 2003 machine, the service would fail to start when the service was configured to forward internal messages to a syslog server. The failure occurs when the Windows Management Instrumentation (WMI) service has not yet started. The installation has been updated to install the service with a dependency on WMI. If the software was previously installed, you must uninstall and then re-install for this change to take effect. Added help to the search dialog and simple filter criteria dialog for event ID and/or/range rules. In previous builds an object reference error was through when a real-time monitor was configured to send a HTML formatted email message in response to no entries being received that passed the assigned filter within a time period. --------------------------------------------------------------------------- Build 8.0.0.54 - Wed, 15 Oct 2008 01:15:19 MDT --------------------------------------------------------------------------- In previous builds many users created email notifications and reports that applied very broad filter criteria causing huge emails to be sent. In many cases the emails were so large the email function failed due to a lack of memory. The email functions now limit the number of entries to 2000. Please let us know if 2000 is too limiting and we will consider adding this value as an option. All scheduled routines can now be disabled on specific days of the week. --------------------------------------------------------------------------- Build 8.0.0.53 - Sun, 28 Sep 2008 10:33:17 MDT --------------------------------------------------------------------------- We have added an extensive tutorial that walks users through different consolidation configurations and archive procedures. In previous builds when loading an auxiliary data source the archive tree nodes within the Downloaded Logs view did not display. This bug has been fixed. In previous builds when a user added an auxiliary data source or changed an already configured auxiliary data source, if the user did not click the Apply button the Options dialog would close without prompting the user to save the changes. The Options dialog now prompts the user to save the changes. When sending HTML emails and exporting to HTML, the event type and log name now colored. Information is blue, warning is orange, error is red, success audit is green, failure audit is red, application log is dark green, system log is dark blue, and security log is dark red. In previous builds frequency detection reports only allowed users to see entries that occurred more than once within the time period. This was a problem when, for example, the administrator wanted to see the total count of a particular entry per day. If the entry only appeared once, the frequency detection report did not include the entry within the report. The Report Wizard has been modified to allow users to specify more than 0 times per unit of time. When 0 is specified any instance of the entry causes the frequency detection report to display the entry. The Filters dialog now allows users to copy a filter to a new filter. In previous builds the toolbar and menu bar items did not properly enable in a few very specific instances. These bugs have been fixed. We have added a tutorial that explains how to create a daily report that contains a count of specific entries. This tutorial shows, for example, how a user can receive a daily email that lists the number of times a service was started the previous day. When exporting the current view to a file, users are now prompted to automatically open the new file. Users can now display downloaded log entries and log properties when right clicking on a download log status item from within the System Status view. Users can now create a view from a current merge. Simply right click within the detail view and select Save As View. In previous builds when right clicking within the Downloaded Logs or Reports and Views view on a tree node the popup menu item would flicker. The popup menu item no longer flickers. In previous builds when viewing event log entries via the Filter Action Events (events that passed assigned filter criteria during a download) the current event type filters and selected filter were applied (toolbar event type toggles and filters combo box). Network Event Viewer now sets all the event type filters and clears the selected filter enabling all entries selected within the checked Filter Action Events nodes to display as expected. In previous builds users would receive an object reference error when attempting to download logs from a lower cased mapped computer within the Network view. This bug has been fixed. The map computer dialog no longer allows users to see the assigned password. --------------------------------------------------------------------------- Build 8.0.0.50 - Tue, 23 Sep 2008 03:00:12 MDT --------------------------------------------------------------------------- In previous builds when downloading event log entries all entries were saved to the data repository. Users can now apply a consolidation filter that limits the saved entries to those that pass the assigned filter. Use the Configuration Wizard to apply a consolidation filter. Please note, while making changes to the Configuration Wizard some of the icons and layout were modified. The configuration templates did not save download filters and actions or any of the real-time parameters. The templates have been updated to save these parameters. The Active Directory Auto Configurator did not skip computers listed in the exclusion list. This bug has been fixed. Users can create a new action based on a current action. From the Actions Manager select the action to base the new action on and then click Copy. The action configuration dialogs have been moved from the application library to our Corner Bowl Software common library enabling code reuse between all our applications. Please note there are several minor user interface differences. We have boosted the syslog forward action performance. Previously the UDP socket was recreated for every entry forwarded. The UDP socket is now cached. When storing logs using MySQL there in some cases the archive function threw an error causing the archive to fail. This bug has been fixed. The export to CSV had a bug in it that caused the log name to appear twice which shifted the column content from the column headers. This bug has been fixed. When sending email alerts in response to entries passing filter criteria during a download the text emails (non-HTML) did not use the user configured settings. Instead a hard coded format was used. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.46 - Thu, 11 Sep 2008 11:59:20 MDT --------------------------------------------------------------------------- Users can now quickly add an event to a filter with just a few clicks of the mouse. To add an entry to a filter, right click on an event log entry and select Filter Selected Event. Once the Filter Selected Event dialog is loaded, specify if you want to show or hide the event in question. Select if you want to create a new filter or append the criteria to an existing filter. If creating a new filter, specify if you want to create a simple or complex filter. Finally, choose if you want to create the filter and apply the new filter to the current view, create the filter and review the criteria within the Filters dialog, or create the filter without applying the filter to the current view. When creating simple filters users can now specify multiple event IDs by separating each event ID with a comma. A range can be specified by separating the values with a dash. For example, 100,200,300-400. The email and HTML templates have been modified to include a footer that includes the name and location the of software that generated the document. In previous builds filter criteria time values were displayed in US locale format. All filter criteria time fields are now displayed in the current locale. In previous builds when importing a configuration to a system that uses a different locale than the system that generated the configuration, the filters did not import properly. This bug has been fixed. Users now have the capability to suppress alerts and actions. Users configure alert and action suppression via the Configuration Wizard or Syslog Configuration Wizard. Once configured, the service will assign an alert flag to the real-time monitor upon an entry passing assigned filter criteria. Once the alert flag is set, filtered entries are ignored until the flag is cleared. The user can configure the alert flag to automatically clear after a period of time, for example after an hour, or the user can manually clear the flag via the user interface. Once cleared the next entry that passes the real-time monitor’s filter criteria will fire. Users can now specify to exclude weekends when scheduling downloads and reports. When creating new complex filter criteria, the user specified DateTime control associated with time criteria would show the current date and time. The behavior has been changed so the current date is shown but the time is set to 12:00 AM. --------------------------------------------------------------------------- Build 8.0.0.41 - Wed, 27 Aug 2008 03:22:08 MDT --------------------------------------------------------------------------- Users can now configure the user interface to optionally hide the System Status window at startup as well as automatically show the Syslog Viewer window at startup. To set these options select Options from the Tools menu item. Select the Display tab. Use the Display tab on the Options dialog to set these options. The options are listed under the Startup section. The Top Events tab within the Log Properties Dialog now creates a graphical representation of the tabular output. Note that events less than 5% of the total report results are grouped together. When an empty top events query was returned from the Log Properties dialog there was no indicator the query returned an empty result set. A message is now displayed. The top events query did not properly execute the Last X Hours query. This bug has been fixed. The Log Properties had a bad link to the help file. This bug has been fixed. A real-time monitor tutorial was added to the help file. The SQL Server tutorial has been replaced with a new tutorial that targets SQL Server 2005. In previous builds the Filters toolbar combo box was not updated after closing the Report and View Wizard. If the user added a new filter or removed an old filter the changes would not reflect in the Filters toolbar combo box. This bug has been fixed. In rare cases when adding a computer to a report or view via the Report and View Wizard the same computer name may have appeared once in lower case and again in upper case. This bug has been fixed. When configuring a single computer within the Configuration Wizard, the domain combo box had no effect on the login credentials. This bug has been fixed. In previous builds when changing the event log repository type (for example from file system to MySQL) the Mapped Computers tree node within the Network View was permanently deleted from the view. This bug has been fixed. The Configuration Wizard now enables users to select and de-select all the logs displayed within the Logs tab. In previous builds when adding a filter from within the Configuration Wizard or Syslog Configuration Wizard new filters were not automatically assigned and/or selected when the user clicked the Select button from within the Filters dialog box. The filter is now automatically assigned if not already assigned. Once assigned the filter is selected within the assigned filters list box. In previous builds When configuring multiple computers and checking or un-checking a log from the logs list box, the wizard may not have prompted the user to save their changes. This bug has been fixed. In previous builds when an invalid syslog packet was received the error message written to the service log did not include the message received. The behavior has been modified to include the data. This modification will help us identify alternate syslog message formats in use. When using MySQL to consolidate logs, if the user interface initially loaded with the Reports and Views navigation window item selected, and the user opened the Reports and Views wizard, the wizard would attempt to connect to SQL Server instead of MySQL when retrieving a list of available logs. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.38 - Sat, 23 Aug 2008 11:16:33 MDT --------------------------------------------------------------------------- Both the Output view and Service Output view did not display application log entries when run on specific locales. For example, when run on Italian operating systems both the Output view and Service view would remain empty thought out execution time. From the Report and View Wizard, when browsing for the file to save a report to or the HTML template to apply, the save as dialog did not automatically navigate to the location of the current setting. This bug has been fixed. When clicking the Restore Defaults button on the Actions tab of the Report and View Wizard, the Email and HTML output template was not updated. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.37 - Fri, 08 Aug 2008 02:52:12 MDT --------------------------------------------------------------------------- This build includes an email limiter or spam control. To configure the email limiter select Options from the Tools menu item. From the Mail Connection tab, enable the email limiter and specify the maximum number of emails to fire and the period to apply the rules. In previous builds Network Event Viewer did not support Unicode operating systems when consolidating logs using the file system. This limitation has been resolved. Please note when upgrading the Filter Action Events view will be empty as the format of the file has changed. This view will automatically rebuild over time. In previous builds all non-user interface actions were saved to a file called ‘alerts7009’. This file is used by the tray icon to fire user interface alerts. Non-user interface actions were previously added to this file so we could someday add a user interface component that showed all actions fired. Since this functionality already exists in the filter action events log we decided to remove this functionality from the alerts file possibly significantly decreasing the alerts file size which in turn decreases the CPU foot print when the tray icon starts up. Message box alerts can now be minimized enabling users to look at previous alerts at any time. A menu item has also been added to the tray icon popup menu to enable users to re-open the message box alert dialog after it has been closed. Users can now start a process or a batch file when an entry passes filter criteria. --------------------------------------------------------------------------- Build 8.0.0.36 - Tue, 01 Jul 2008 09:54:58 MDT --------------------------------------------------------------------------- When attempting to delete a configuration and the logical group is checked, at least one computer under the logical group is not checked, and at least one computer under the logical group is checked an error was thrown. This bug has been fixed. --------------------------------------------------------------------------- Build 8.0.0.35 - Thu, 26 Jun 2008 10:31:12 MDT --------------------------------------------------------------------------- The download algorithm sorts entries prior to committing them to the log repository. When downloading logs to a database and no filters are assigned to the download configuration, there is no need to sort the entries prior to committing them to the database. In this scenario, the algorithm has been modified to bypass the sort. Users should now see significant performance gains when downloading large logs to a database and there are no download filters assigned. In previous builds there was no way to assign a non-standard port to the MySQL configuration. Users can now specify the port to connect by appending “:1234” to the end of the host name. In previous builds the popup menu re-displayed after deleting a log from the Downloaded Logs view. The popup menu no longer re-displays. When viewing the Filter Actions Events or Reports and Views tabs within the Navigation window, users may have seen a cast error thrown when attempting to open the Syslog Configuration Wizard. This bug has been fixed. In prior builds the MySQL archive function might have failed throwing the following error: Duplicate entry ‘X’ for key 1. This bug has been fixed. In previous builds users would see an object reference error thrown when attempting to delete a filter when a report was configured without any filter specified. This bug has been fixed. When creating a standard report, users can now include and