<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GoCloudy Blog</title>
	<atom:link href="http://gocloudy.info/feed/" rel="self" type="application/rss+xml" />
	<link>http://gocloudy.info</link>
	<description>Clouds Talks and More</description>
	<lastBuildDate>Wed, 25 Jan 2012 01:42:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='gocloudy.info' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>GoCloudy Blog</title>
		<link>http://gocloudy.info</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://gocloudy.info/osd.xml" title="GoCloudy Blog" />
	<atom:link rel='hub' href='http://gocloudy.info/?pushpress=hub'/>
		<item>
		<title>Latest and greatest InTrust version 10.4 comes out of the door</title>
		<link>http://gocloudy.info/2012/01/25/latest-and-greatest-intrust-version-10-4-comes-out-of-the-door/</link>
		<comments>http://gocloudy.info/2012/01/25/latest-and-greatest-intrust-version-10-4-comes-out-of-the-door/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 01:32:36 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Change Auditor]]></category>
		<category><![CDATA[event log management]]></category>
		<category><![CDATA[intrust]]></category>
		<category><![CDATA[Windows auditing]]></category>

		<guid isPermaLink="false">http://alexeykorotich.wordpress.com/?p=196</guid>
		<description><![CDATA[The version 10.4 of InTrust advances in all three main capabilities attributed to successful event log management products. Continue here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=196&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The version 10.4 of InTrust advances in all three main capabilities attributed to successful event log management products. Continue <a href="http://communities.quest.com/community/quest-itexpert/blog/2012/01/24/latest-and-greatest-intrust-version-104-comes-out-the-door">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=196&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2012/01/25/latest-and-greatest-intrust-version-10-4-comes-out-of-the-door/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>Custom InTrust add-in for reporting on DNS debug logs</title>
		<link>http://gocloudy.info/2011/10/27/custom-intrust-add-in-for-reporting-on-dns-debug-logs/</link>
		<comments>http://gocloudy.info/2011/10/27/custom-intrust-add-in-for-reporting-on-dns-debug-logs/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 01:40:35 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[custom addin]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[intrust]]></category>

		<guid isPermaLink="false">http://alexeykorotich.wordpress.com/?p=206</guid>
		<description><![CDATA[I&#8217;m pleased to announce the availability of another custom InTrust add-in extending the product reach to new types of logs. This add-in continues a series of out of band solutions we make available to the InTrust customers outside of the official product release. This time it&#8217;s the add-in that let&#8217;s you collect debug logs generated by Microsoft [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=206&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m pleased to announce the availability of another custom InTrust add-in extending the product reach to new types of logs. This add-in continues a series of out of band solutions we make available to the InTrust customers outside of the official product release.</p>
<p>This time it&#8217;s the add-in that let&#8217;s you collect debug logs generated by Microsoft DNS servers.</p>
<p>Continue <a href="http://communities.quest.com/community/quest-itexpert/blog/2011/10/27/custom-intrust-add-in-for-reporting-on-dns-debug-logs">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/206/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=206&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2011/10/27/custom-intrust-add-in-for-reporting-on-dns-debug-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>OnDemand Log Management: Now supporting syslog, agent less collection and more</title>
		<link>http://gocloudy.info/2011/08/25/201/</link>
		<comments>http://gocloudy.info/2011/08/25/201/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 01:35:26 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OLM Feature Update]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[event log management]]></category>
		<category><![CDATA[hub agents]]></category>
		<category><![CDATA[ondemand log management]]></category>
		<category><![CDATA[syslog]]></category>

		<guid isPermaLink="false">http://alexeykorotich.wordpress.com/?p=201</guid>
		<description><![CDATA[OnDemand Log Management gets exciting new features that help you comply with IT regulations, stay on top of changes to critical IT resources and detect and react to security issues. Continue here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=201&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>OnDemand Log Management gets exciting new features that help you comply with IT regulations, stay on top of changes to critical IT resources and detect and react to security issues. Continue <a href="http://communities.quest.com/community/quest-itexpert/blog/2011/08/09/ondemand-log-management-now-supporting-syslog-agent-less-collection-and-more">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/201/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=201&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2011/08/25/201/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>Stay on top of security issues with OnDemand Log Management</title>
		<link>http://gocloudy.info/2011/01/27/stay-on-top-of-security-issues-with-ondemand-log-management/</link>
		<comments>http://gocloudy.info/2011/01/27/stay-on-top-of-security-issues-with-ondemand-log-management/#comments</comments>
		<pubDate>Thu, 27 Jan 2011 20:40:44 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OnDemand]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[change tracking]]></category>
		<category><![CDATA[evidence report]]></category>
		<category><![CDATA[investigation]]></category>
		<category><![CDATA[ondemand log management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=185</guid>
		<description><![CDATA[You tell me how important it is to keep a close eye on the Holy Grail of most IT environments today &#8211; Microsoft Active Directory.  No one else can solve this pain for you in a more elegant way than OnDemand Log Management with its extended auditing capability which covers Active Directory and other IT infrastructure components. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=185&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You tell me how important it is to keep a close eye on the Holy Grail of most IT environments today &#8211; Microsoft Active Directory.  No one else can solve this pain for you in a more elegant way than <a href="http://www.quest.com/ondemand-log-management/">OnDemand Log Management</a> with its extended auditing capability which covers Active Directory and other IT <a href="http://gocloudy.info/2010/12/03/extended-auditing-for-active-directory-and-file-servers-now-available-in-ondemand-log-management/">infrastructure components</a>.</p>
<p style="text-align:left;">In this short <a href="http://www.youtube.com/watch?v=eeQdQWF43eo">video </a>watch how subscription bases OnDemand Log Management lets you:</p>
<ol>
<li><strong>Easily set up comprehensive tracking of all changes</strong> made to Active Directory irregardless of the native auditing configuration</li>
<li><strong>Perform investigation of security issue</strong>s by giving you tools to effectively search and analyze audit trails</li>
<li><strong>Take proactive measure</strong>s to prevent security incidents from happening in the future</li>
<li><strong>Prepare evidence reports</strong> suitable for presenting to CSOs and external auditors</li>
</ol>
<p style="text-align:left;"><span style="font-family:monospace;"><span style="text-align:center; display: block;"><a href="http://gocloudy.info/2011/01/27/stay-on-top-of-security-issues-with-ondemand-log-management/"><img src="http://img.youtube.com/vi/eeQdQWF43eo/2.jpg" alt="" /></a></span><br />
</span></p>
<p style="text-align:left;">Want to conduct your own investigation now?</p>
<p style="text-align:left;">Sign up for a full functional <a href="http://www.quest.com/ondemand-log-management/">trial </a>and let us know how it goes.</p>
<p style="text-align:left;">Alexey</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/185/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=185&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2011/01/27/stay-on-top-of-security-issues-with-ondemand-log-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>A better way to do custom reporting</title>
		<link>http://gocloudy.info/2010/12/23/a-better-way-to-do-custom-reporting/</link>
		<comments>http://gocloudy.info/2010/12/23/a-better-way-to-do-custom-reporting/#comments</comments>
		<pubDate>Thu, 23 Dec 2010 03:21:47 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OLM Feature Update]]></category>
		<category><![CDATA[custom reporting]]></category>
		<category><![CDATA[event trend analysis]]></category>
		<category><![CDATA[ondemand log management]]></category>
		<category><![CDATA[search export]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=173</guid>
		<description><![CDATA[As the year wraps up and the Christmas Eve rapidly approaches we&#8217;re making some exciting updates to the OnDemand Log Management we want you to hear about. We&#8217;re pleased to offer a brand new custom reporting functionality that not only allows you to run any of the pre-defined reports but also build your own with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=173&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As the year wraps up and the Christmas Eve rapidly approaches we&#8217;re making some exciting updates to the OnDemand Log Management we want you to hear about.</p>
<p>We&#8217;re pleased to offer a brand new custom reporting functionality that not only allows you to run any of the pre-defined reports but also build your own with the same ease.</p>
<p>The new export to PDF feature came to replace the old way of reporting that is now gone as is the Reports tab where you&#8217;d previously find it. Check out this short video that shows the new and straightforward process of building custom reports based on favorite searches. Now it literally takes the same amount of time as the video runs.</p>
<span style="text-align:center; display: block;"><a href="http://gocloudy.info/2010/12/23/a-better-way-to-do-custom-reporting/"><img src="http://img.youtube.com/vi/J8TGWU_bbs0/2.jpg" alt="" /></a></span>
<p>Wait, we&#8217;ve got some more news for you.</p>
<p>If you take a closer look to the home page of the product you&#8217;ll notice that it now contains another chart which lets you quickly assess the state of alerts you configured for your environment. Here is the sample screenshot of the Top Alerts chart:</p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/12/chart_topalerts.jpg"><img class="aligncenter size-full wp-image-177" title="chart_topalerts" src="http://alexeykorotich.files.wordpress.com/2010/12/chart_topalerts.jpg?w=450" alt=""   /></a></p>
<p>Lucky owners of the commercial service subscription get another handy tool. With a help of Events by Time chart you can do basic trend analysis and watch for unusual event peaks. Here is a sample of this chart as well.</p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/12/chart_eventtime.jpg"><img class="aligncenter size-full wp-image-178" title="chart_eventtime" src="http://alexeykorotich.files.wordpress.com/2010/12/chart_eventtime.jpg?w=450" alt=""   /></a></p>
<p>Both new charts have interactive features and drill down capability which instantly sets you up for further investigation.</p>
<p>We look forward to continuing expanding the product feature set throughout the next year.</p>
<p>Happy holidays!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=173&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/12/23/a-better-way-to-do-custom-reporting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/chart_topalerts.jpg" medium="image">
			<media:title type="html">chart_topalerts</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/chart_eventtime.jpg" medium="image">
			<media:title type="html">chart_eventtime</media:title>
		</media:content>
	</item>
		<item>
		<title>Extended Auditing for Active Directory and File Servers now available in OnDemand Log Management</title>
		<link>http://gocloudy.info/2010/12/03/extended-auditing-for-active-directory-and-file-servers-now-available-in-ondemand-log-management/</link>
		<comments>http://gocloudy.info/2010/12/03/extended-auditing-for-active-directory-and-file-servers-now-available-in-ondemand-log-management/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 22:52:44 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OLM Feature Update]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[file server]]></category>
		<category><![CDATA[ondemand log management]]></category>
		<category><![CDATA[Windows auditing]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=131</guid>
		<description><![CDATA[I&#8217;m sure many of IT admins happened to have this poor feeling when they couldn&#8217;t get from the logs a piece of information they were looking for. Partly because they didn&#8217;t have an appropriate log management tool in place. Partly because the logs themselves didn&#8217;t provide the level of details admins expected them to provide. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=131&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure many of IT admins happened to have this poor feeling when they couldn&#8217;t get from the logs a piece of information they were looking for. Partly because they didn&#8217;t have an appropriate log management tool in place. Partly because the logs themselves didn&#8217;t provide the level of details admins expected them to provide. It becomes especially frustrating in the change management world. If logs you rely on can&#8217;t give a full picture of the change that was made in the past how can you conduct a thorough change review to make sure that every change is made for a reason and according to your security policies?</p>
<p>Quite a few of the early adopters of <a href="http://www.quest.com/ondemand-log-management/">OnDemand Log Management</a> echoed this concern. As you know we&#8217;ve been listening to your feedback very carefully so we addressed this concern with the recent introduction of the so called <strong>Extended Auditing for Active Directory and File Servers</strong>. It&#8217;s Extended Auditing because it provides additional level of details compared to what you can extract from the native operating system or application logs.</p>
<p>Extended Auditing is instantly available to all of existing and yet to come customers of OnDemand Log Management. It is activated in the agent installation wizard by selecting Extended Auditing option as shown below. Just keep in mind that these options will only show up when you&#8217;re installing the agent to the server OS holding the corresponding server role: Active Directory server or file server.</p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/12/agentsetup.jpg"></a><a href="http://alexeykorotich.files.wordpress.com/2010/12/agentsetup.jpg"><img class="aligncenter size-full wp-image-134" title="AgentSetup" src="http://alexeykorotich.files.wordpress.com/2010/12/agentsetup.jpg?w=450&#038;h=339" alt="" width="450" height="339" /></a></p>
<p>Once you&#8217;ve let the agent capture first changes to your Active Directory objects or files and directories you can instantly view them by using one of the predefined searches that end with <em>(Extended Auditing)</em></p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/12/predefinedsearches.jpg"><img class="aligncenter size-full wp-image-138" title="PredefinedSearches" src="http://alexeykorotich.files.wordpress.com/2010/12/predefinedsearches.jpg?w=450&#038;h=279" alt="" width="450" height="279" /></a></p>
<p>In this post I&#8217;m going to go through top 5 reasons why Extended Auditing gives you additional piece of mind from the change management standpoint. So, here they go</p>
<p><strong>1. Capturing originator&#8217;s IP address</strong></p>
<p>Unlike with Object Access events from the native Security log with Extended Auditing you can trace all changes down to a workstation from which the change originated. So, if multiple people in your organization use the same administrative account to perform their duty you could possibly distinguish between them by looking up the IP address they used.</p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpropchange.jpg"></a><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpropchange.jpg"><img class="aligncenter size-full wp-image-137" title="Extended_ADPropChange" src="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpropchange.jpg?w=450&#038;h=117" alt="" width="450" height="117" /></a><br />
<strong>2. Full Active Directory change auditing down to the attribute level with before and after values</strong></p>
<p>As the screenshot above shows for each change being made to Active Directory Extended Auditing scrupulously seizes all the details including the object attribute and more importantly the before and after values.  Not only you can replay a sequence of changes made to Active Directory within a specified time period but also roll them back if they deem inappropriate. Unlike with the native Windows auditing subsystem there is no need to go through a time consuming process of setting up the auditing configuration. Once Extended Auditing for Active Directory is enabled it immediately starts intercepting changes and change attempts to all objects in Active Directory.</p>
<p><strong>3. Group Policy settings change auditing</strong></p>
<p>The only indication of changes ever made to Group Policy configuration that can be found in the native Security log is an event like this below. Unfortunately, no way it&#8217;d tell you whether this change concerned one of the security policies like Account Lockout Policy or it just targeted one of the application configuration settings.</p>
<p><strong><a href="http://alexeykorotich.files.wordpress.com/2010/12/native_adgpochange.jpg"><img class="aligncenter size-full wp-image-146" title="Native_ADGPOChange" src="http://alexeykorotich.files.wordpress.com/2010/12/native_adgpochange.jpg?w=450&#038;h=263" alt="" width="450" height="263" /></a></strong></p>
<p>Compare this to the event you&#8217;d get with a help of Extended Auditing in OnDemand Log Management. In addition to the name of the Group Policy object you would easily see both the name of the affected setting and its before and values!</p>
<p><strong><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_adgpochange.jpg"><img class="aligncenter size-full wp-image-141" title="Extended_ADGPOChange" src="http://alexeykorotich.files.wordpress.com/2010/12/extended_adgpochange.jpg?w=450&#038;h=92" alt="" width="450" height="92" /></a></strong></p>
<p><strong>4. Detailed permission change tracking</strong></p>
<p>Those of you that can&#8217;t read with naked eye a lengthy sequence of hexadecimal numbers will have no clue who actually was granted or revoked what permissions to a file or Active Directory object. Simply because this is how Windows stores permissions in the object&#8217;s security descriptor and native event logs don&#8217;t bother decrypting this format.</p>
<p>Extended Auditing makes things a way easier by breaking each permission change down into a series of events in which you can clearly see what user or group was granted or revoked which permission to the file or Active Directory object in question.</p>
<p><strong><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpermchange.jpg"><img class="aligncenter size-full wp-image-143" title="Extended_ADPermChange" src="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpermchange.jpg?w=450&#038;h=157" alt="" width="450" height="157" /></a></strong></p>
<p><strong>5. Accurate file and share access auditing</strong></p>
<p>As you know due to the implementation details of the Windows auditing subsystem the accuracy of file access audit events really depends on how well behaved the application that works with those files is. It can turn into a real mess when a lot of file activity happens behind the scenes which is the case with <a href="http://blogs.msdn.com/b/ericfitz/archive/2006/10/26/how-are-object-access-events-generated.aspx">Microsoft Word</a>.</p>
<p>Extended Auditing for File Servers brings that mess in order. However complex the underlying file manipulations are it will always capture the real operations performed on a file, directory or share. So instead of having to guess whether this file open event actually resulted in a subsequent file write or not you&#8217;ll know for sure when the file was changed, deleted or moved.</p>
<p><strong><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_fileeventlist.jpg"></a><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_fileeventlist1.jpg"><img class="aligncenter size-full wp-image-150" title="Extended_FileEventList" src="http://alexeykorotich.files.wordpress.com/2010/12/extended_fileeventlist1.jpg?w=450&#038;h=69" alt="" width="450" height="69" /></a></strong></p>
<p>And for every file access event you&#8217;ll get the entire picture including the file operation, the name and IP of the user who made the change and the application executable that carried out the request on the user&#8217;s behalf.</p>
<p><strong><a href="http://alexeykorotich.files.wordpress.com/2010/12/extended_filemodified.jpg"><img class="aligncenter size-full wp-image-144" title="Extended_FileModified" src="http://alexeykorotich.files.wordpress.com/2010/12/extended_filemodified.jpg?w=450&#038;h=103" alt="" width="450" height="103" /></a></strong></p>
<p>As you might guess there are many other cases where Extended Auditing does a much better job capturing every single aspect of a change being made to files, folders, shares and Active Directory objects. And the best way to feel it is to give it a free try <a href="https://portal.ondemand.quest.com/Register/NewSSOUser">by yourself</a>.</p>
<p>With the help of Extended Auditing you can bring change management processes to an absolutely new level where tight and all encompassing control of changes becomes a reality.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/131/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=131&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/12/03/extended-auditing-for-active-directory-and-file-servers-now-available-in-ondemand-log-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/agentsetup.jpg" medium="image">
			<media:title type="html">AgentSetup</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/predefinedsearches.jpg" medium="image">
			<media:title type="html">PredefinedSearches</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpropchange.jpg" medium="image">
			<media:title type="html">Extended_ADPropChange</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/native_adgpochange.jpg" medium="image">
			<media:title type="html">Native_ADGPOChange</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/extended_adgpochange.jpg" medium="image">
			<media:title type="html">Extended_ADGPOChange</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/extended_adpermchange.jpg" medium="image">
			<media:title type="html">Extended_ADPermChange</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/extended_fileeventlist1.jpg" medium="image">
			<media:title type="html">Extended_FileEventList</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/12/extended_filemodified.jpg" medium="image">
			<media:title type="html">Extended_FileModified</media:title>
		</media:content>
	</item>
		<item>
		<title>CloudCamp experience</title>
		<link>http://gocloudy.info/2010/11/11/cloudslam-experience-and-paas/</link>
		<comments>http://gocloudy.info/2010/11/11/cloudslam-experience-and-paas/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 01:50:22 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[CloudCamp]]></category>
		<category><![CDATA[Google AppEngine]]></category>
		<category><![CDATA[IaaS]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[PaaS]]></category>
		<category><![CDATA[RightScale]]></category>
		<category><![CDATA[Scalr]]></category>
		<category><![CDATA[Toad]]></category>
		<category><![CDATA[typhoonae]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=122</guid>
		<description><![CDATA[I wanted to drop a note about an unusual cloud event I recently attended in San Francisco. CloudCamp is a half day conference related to trends in cloud technologies. It’s held throughout the world and supported by well known experts and companies in the cloud industry. It was a 4 hour event packed with a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=122&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wanted to drop a note about an unusual cloud event I recently attended  in San Francisco.</p>
<p><a href="http://cloudcamp.org/">CloudCamp </a>is a half day conference related to trends in cloud technologies. It’s held throughout the world and supported by well known experts and companies in the cloud industry.<br />
It was a 4 hour event packed with a lot of interesting content and discussions. I liked the idea that attendees could submit topics for discussions and a self nominated panel of cloud experts could pick up any questions they felt comfortable answering over the beer <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .<br />
The event started with vendor sponsored enlightening talks. Speakers were teaching the audience what’s unique about the cloud restraining from pitching their own tools.<br />
<a href="https://scalr.net/"> Scalr</a> and <a href="http://www.rightscale.com/">RighScale </a>shared VM pattern based approaches they use to efficiently scale cloud applications up and out. <a href="http://facility9.com/">Jeremiah Peschka</a> from <a href="http://www.quest.com/">Quest Software</a> raised the importance of NoSQL databases and explained how <a href="http://www.quest.com/toad-for-cloud-databases/">Toad for Cloud Databases</a> can help developers interact with cloud databases in the way they’ve been doing with traditional RDBMs.<br />
<a href="http://perfcap.blogspot.com/"> Adrian Cockroft</a> from Netflix talked about the company’s experience with the recent infrastructure migration to Amazon EC2 (which turned out being a complete rewrite) and what they would like to see provided by yet to mature NoSQL databases. Other presentations were delivered by guys from IBM, Tropo and Twilio.</p>
<p>Everyone agreed that security, reliability and NoSQL will continue being the cloud buzz words throughout 2011.</p>
<p>The break out session on PaaS held by <a href="http://blog.stadil.com/">Sebastian Stadil</a> was of particular interest to me. Today most of the cloud derived value comes from IaaS while PaaS still has to go a long way to become an attractive alternative to traditional development platforms.<br />
The group was debating when leveraging PaaS can make sense today. The agreement was the PaaS might be a good start for a “two guys in the garage” startup to quickly spin up their startup project. It becomes more difficult to stick with the PaaS of choice when the service grows and you have to keep up with the increasing demand at the same time staying profitable and not locking yourself into a single platform vendor.</p>
<p>This is when open source projects  can play very important role to bridge the gap.  Announced at the event the project <a href="http://code.google.com/p/typhoonae/">typhoonae</a> is an open source implementation of <a href="http://code.google.com/appengine/docs/">Google AppEngine API</a> that can run in any virtual environment. Its flexible architecture let’s you plug in any NoSQL database as a storage backend while making transparent the migration from Google AppEngine PaaS to your choice of IaaS. So, if down the road you’ve learned that for your type of application immediate data consistency can be traded off in favor of constant data availability you could easily switch from say Google Big Table to Cassandra or MongoDB running in Amazon EC2.</p>
<p>Apparently, over the course of the next couple of years we’ll continue seeing the convergence of IaaS and PaaS . For cloud providers this is the only viable way to provide a rapid development platform for highly available, massive data processing applications and cut the cost of on premise applications migration. What an interesting age we’re living in!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/122/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=122&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/11/11/cloudslam-experience-and-paas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>Get critical events in real time to your inbox</title>
		<link>http://gocloudy.info/2010/10/21/get-critical-events-in-real-time-to-your-inbox/</link>
		<comments>http://gocloudy.info/2010/10/21/get-critical-events-in-real-time-to-your-inbox/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 22:56:35 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OLM Feature Update]]></category>
		<category><![CDATA[account lockouts]]></category>
		<category><![CDATA[alerts]]></category>
		<category><![CDATA[event log management]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[OnDemand]]></category>
		<category><![CDATA[ondemand log management]]></category>
		<category><![CDATA[real time]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=96</guid>
		<description><![CDATA[Have you ever caught yourself thinking that you don&#8217;t actually know what you should be searching for when you are on the Search tab of the nice and slick OnDemand Log Management UI? Have you ever questioned yourself why you have to check for critical events by yourself instead of having the product do that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=96&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Have you ever caught yourself thinking that you don&#8217;t actually know what you should be searching for when you are on the Search tab of the nice and slick <a href="https://portal.ondemand.quest.com/Register/NewSSOUser">OnDemand Log Management</a> UI?</p>
<p>Have you ever questioned yourself why you have to check for critical events by yourself instead of having the product do that for your and only interfere with your other business when your attention is really required?</p>
<p>I did and so did quite a few of you according to the feedback you&#8217;ve been generously sharing with this. So I&#8217;m pleased to tell you that you&#8217;ve been heard!</p>
<p>During last couple of weeks we made a couple of exiting feature updates for you.</p>
<p>Now every time you log into the event log management service you can start with any of the pre-defined searches which we put for all service users or you happened to craft by yourself some time ago and found helpful enough for ongoing use.  You can customize any of the pre-defined searches down the road by adding column filters, adjusting the search criteria and changing the set of fields being displayed in the results view. Finally found a needle in the haystack and want to save the time you spent on building the resulting query? Just add your search to the favorites and start with it next time.</p>
<p>Check out a set of the canned searches we provide for you today and <a href="https://questondemand.uservoice.com/forums/49421-general?lang=en&amp;utm_campaign=Widgets&amp;utm_content=tab-widget&amp;utm_medium=Popin+Widget&amp;utm_source=questondemand.uservoice.com">tell us</a> what&#8217;s missing!</p>
<p>Favorite searches is not just a shortcut to start an investigation. Any saved search can now be run in real time against every new event that is collected from your entire network. All events matching the search criteria that you defined in your alert-enabled searches will be immediately sent to the specified email address. Don’t want to be spammed by notifications? Subscribe do hourly or daily digests with a full list of critical events.</p>
<p>See the nice and concise video on the Dmitry&#8217;s <a href="http://cloudenterprise.info/2010/10/21/cloud-with-an-eagle-eye/">blog </a>that  clearly shows how easy setting up alerts really is</p>
<p>So, now OnDemand Log Management can be used in entirely unattended mode. If you don&#8217;t have much time to do daily analysis right in the service UI then just set up alerts and get back to your business – the service will take care of all the important things happening in your network.</p>
<p>It&#8217;s nice to see how the cloud based event log management service is becoming a neat operation tool. Indeed alert enabled searches set you up for monitoring of security incidents and operational issues.  And the same searches can be later used to find the root cause of the issue by looking up events that preceded it.</p>
<p>See another video that shows how OnDemand Log Management can help you track and investigate one of the most distracting operational issues these days &#8211; service account lockouts.</p>
<span style="text-align:center; display: block;"><a href="http://gocloudy.info/2010/10/21/get-critical-events-in-real-time-to-your-inbox/"><img src="http://img.youtube.com/vi/bE6hTAnTqnQ/2.jpg" alt="" /></a></span>
<p>Stay tuned.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/96/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=96&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/10/21/get-critical-events-in-real-time-to-your-inbox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>Try OnDemand and win an iPad!</title>
		<link>http://gocloudy.info/2010/10/05/try-ondemand-and-win-an-ipad/</link>
		<comments>http://gocloudy.info/2010/10/05/try-ondemand-and-win-an-ipad/#comments</comments>
		<pubDate>Tue, 05 Oct 2010 05:54:31 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OnDemand]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=79</guid>
		<description><![CDATA[You might already know that Quest&#8217;s subsidiary ScriptLogic is hosting an evaluation contest for OnDemand trial users. If you happen to be one of the first 75 participants who subscribed to one of the OnDemand services and provided the evaluation feedback you&#8217;ll be rewarded with a 50$ Amazon gift card. Completing the survey takes 5 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=79&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You might already know that Quest&#8217;s subsidiary <a href="http://www.scriptlogic.com/">ScriptLogic</a> is hosting an evaluation <a href="http://www.scriptlogic.com/landing/ondemand/promo.asp">contest</a> for OnDemand trial users. If you happen to be one of the first 75 participants who subscribed to one of the OnDemand services and provided the evaluation feedback you&#8217;ll be rewarded with a 50$ Amazon gift card. Completing the survey takes 5 minutes of your time yet helps us set the right priorities for the future product development.</p>
<p>Provide thorough and fair feedback about any of the OnDemand products and you&#8217;ll participate in a draw to win one of the 2 iPads!</p>
<p>I think that I&#8217;ll share one hint with you here &#8211; your chances will double if you provide feedback about both of the OnDemand services: OnDemand Recovery for AD and OnDemand Log Management.</p>
<p>Feel free to provide any likes and dislikes about OnDemand and we won&#8217;t make you wait for too long until your feedback find its way into the product.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=79&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/10/05/try-ondemand-and-win-an-ipad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>
	</item>
		<item>
		<title>OnDemand Log Management feature update in September</title>
		<link>http://gocloudy.info/2010/09/30/ondemand-log-management-feature-update-in-september/</link>
		<comments>http://gocloudy.info/2010/09/30/ondemand-log-management-feature-update-in-september/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 04:54:57 +0000</pubDate>
		<dc:creator>Alexey Korotich</dc:creator>
				<category><![CDATA[OLM Feature Update]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[feature update]]></category>
		<category><![CDATA[full text search]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[OnDemand]]></category>
		<category><![CDATA[search]]></category>

		<guid isPermaLink="false">http://gocloudy.info/?p=84</guid>
		<description><![CDATA[In this edition of the OnDemand Log Management new features review I&#8217;m going to familiarize yourself with the exciting changes we made to the core function of the product recently &#8211; events search. There are many ways people search data today. The main factor that influence our search behavior is the nature of the actual [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=84&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this edition of the <a href="http://www.quest.com/ondemand-log-management/">OnDemand Log Management</a> new features review I&#8217;m going to familiarize yourself with the exciting changes we made to the core function of the product recently &#8211; events search.</p>
<p>There are many ways people search data today. The main factor that influence our search behavior is the nature of the actual data being searched. If data is unstructured (e.g. web pages, text documents) then full text search becomes your savior. For structured data (Windows events, database records, spreadsheets) it makes much more sense to search by specific parts of the composite record.</p>
<p>In OnDemand Log Management we decided to combine the best of the both worlds. You have the power of Google like search language coupled with familiar Excel like column based filtering.</p>
<p><a href="http://alexeykorotich.files.wordpress.com/2010/10/search1.jpg"><img class="alignnone size-full wp-image-90" title="search" src="http://alexeykorotich.files.wordpress.com/2010/10/search1.jpg?w=450" alt=""   /></a></p>
<p>One search tool nicely complements the other &#8211; start off by putting any word or phrase you&#8217;re looking for in the query box, get the initial results and narrow them down by putting additional criteria in the column filters. For example start your search with <em>&#8220;logons&#8221;</em>, then pick up the EventID field into the events grid and put in only the eventids of logon events you&#8217;re really interested in. Don&#8217;t know what eventids to look for?  Find it out in our online event <a href="http://eventopedia.cloudapp.net/">encyclopedia</a>. Shrink the results further down by putting in the logon name of the user the logon events should be attributed to.</p>
<p>The syntax of the query language we came up with highly resembles  that of Google or Windows 7 desktop search. We don&#8217;t want you to climb a  huge learning curve of mastering yet another query language. Instead we  want you to leverage your existing search skills you arguably apply  every day. Today the language syntax can accommodate both plain words and phrases that can be found anywhere in the event and queries tied to particular fields that can be distinguished in the event. You can construct complex search criteria by stitching the simple parts together with the logical operators like AND and OR. You can also use wildcards to search by a substring that you can only remember (e.g. first N characters of the user name). The full language description along with the sample queries can be found in our online <a href="https://portal.ondemand.quest.com/Help/LogManagement/search.html">Help</a>.</p>
<p>Of course, this is not where we&#8217;re going to stop. We hope that the first version of our query language will help you jump started with constructing basic event queries not requiring you to spend a lot of learning time beforehand. Meanwhile we&#8217;ll be sophisticating the language to let you do more with your event data both already collected and yet to come.</p>
<p>Tell us what you can and can not do with the search tools we put in your hands today! Spend two minutes of your time to vote for existing or submit new product improvement ideas by using this feedback widget that you can find on the left hand side of the product UI</p>
<p><a href="https://questondemand.uservoice.com/forums/49421"><img class="alignnone size-full wp-image-88" title="feedback" src="http://alexeykorotich.files.wordpress.com/2010/10/feedback1.jpg?w=450" alt=""   /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/alexeykorotich.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/alexeykorotich.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/alexeykorotich.wordpress.com/84/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gocloudy.info&amp;blog=12582715&amp;post=84&amp;subd=alexeykorotich&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gocloudy.info/2010/09/30/ondemand-log-management-feature-update-in-september/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8986d207a2a0addca525f007dc03ca48?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alexeykorotich</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/10/search1.jpg" medium="image">
			<media:title type="html">search</media:title>
		</media:content>

		<media:content url="http://alexeykorotich.files.wordpress.com/2010/10/feedback1.jpg" medium="image">
			<media:title type="html">feedback</media:title>
		</media:content>
	</item>
	</channel>
</rss>
