you should start and stop looking here...
http://www.splunk.com use snare on windows to convert event logs to windows and spit them across to a central splunk server. you *could* use syslog-ng for a conventional syslog server (with phpsyslog-ng as a tame and uninspired web interface), but it depends what you want out of the data. i'd strongly suggest starting out with the free version of splunk, it's very slick and web2.0ish. also the new version, 3.0 is currently due in the middle of july, which is looking even slicker so far.