Re: Windows Service - Event Log



On 2006-06-28, Willy Denoyette [MVP] <willy.denoyette@xxxxxxxxxx> wrote:
Who's talking about writing to the eventlog? Tim and I are talking about
writing to the registry ( HKLM ).


Willy.


"Kevin Spencer" <uce@xxxxxxx> wrote in message
news:O5BFphqmGHA.2452@xxxxxxxxxxxxxxxxxxxxxxx
|> Only Administrators (and localsystem) are allowed to write to HKLM and
| > descendants, Service accounts are not supposed to write to HKLM.
|
| Services write to Event Logs all the time, and run under a variety of user
| accounts. In fact, the majority of the Events in the Event Log are written
| by Services. If you look in the Application and System Event Logs, for
| example, you will see that almost all Events are written by Services.
|
| That said, by default, members of the Administrators group and the Local
| System account are the only accounts allowed to write to the Event Log on
a
| Windows 2003 server. On the other hand, a Service can certainly run under
| the Local System Account, and an account other than the Administrators
group
| or the Local System account may be granted permission to create and write
to
| Event Logs as well.
|
| --
| HTH,
|
| Kevin Spencer
| Microsoft MVP
| Professional Chicken Salad Alchemist
|
| Big thicks are made up of lots of little thins.
|
|
| "Willy Denoyette [MVP]" <willy.denoyette@xxxxxxxxxx> wrote in message
| news:OxCE$AqmGHA.4536@xxxxxxxxxxxxxxxxxxxxxxx
| > Yes, but why do you want your service to write to this key?
| > Only Administrators (and localsystem) are allowed to write to HKLM and
| > descendants, Service accounts are not supposed to write to HKLM. If you
| > really need your service to write to HKLM, you need to run as
| > "localsystem".
| > Again if you grant a non privileged account write access to HKLM, you
| > severely compromise your system's security.
| >
| > Willy.
| >
| > "Tim Van Wassenhove" <timvw@xxxxxxxxxxxxxxxxxxxxx> wrote in message
| > news:uuAwDNpmGHA.4992@xxxxxxxxxxxxxxxxxxxxxxx
| > | On 2006-06-28, Willy Denoyette [MVP] <willy.denoyette@xxxxxxxxxx>
wrote:
| > | >
| > | > "Tim Van Wassenhove" <timvw@xxxxxxxxxxxxxxxxxxxxx> wrote in message
| > | > news:e8Jsf8lmGHA.2280@xxxxxxxxxxxxxxxxxxxxxxx
| > | >| On 2006-06-27, pisquem@xxxxxxxxxxx <pisquem@xxxxxxxxxxx> wrote:
| > | >| > I am building an windows service that is to be deployed on a
| > windows
| > | >| > server 2003 and I want to have activity written to the event log,
I
| > | >| > want its own log called ('CustomLog')
| > | >| >
| > | >| > Below is what I have so far...its builds fine but when I go to
| > start
| > | >| > the service i get the following error.
| > | >|
| > | >| When i tried that (on a default windows 2003 installation) i
| > experienced
| > | >| a problem with access rights. If i remember well, i had to give the
| > | >| 'network' user access rights to the registry keys..
| > | >|
| > | >
| > | > What registry key's?
| > |
| > | HKLM/System/CurrentControlSet/Services/Eventlog (or one of it's
| > | children).
| > |
| > |
| > | --
| > | Met vriendelijke groeten,
| > | Tim Van Wassenhove <http://timvw.madoka.be>
| >
| >
|
|




--
Met vriendelijke groeten,
Tim Van Wassenhove <http://timvw.madoka.be>
.



Relevant Pages

  • Re: Windows Service - Event Log
    ... writing to the registry (HKLM). ... | Services write to Event Logs all the time, and run under a variety of user ... | That said, by default, members of the Administrators group and the Local ... | the Local System Account, and an account other than the Administrators ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Windows Service - Event Log
    ... Service accounts are not supposed to write to HKLM. ... Services write to Event Logs all the time, and run under a variety of user ... the Local System Account, and an account other than the Administrators group ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Windows Service - Event Log
    ... writing to the registry (HKLM). ... that I am too) are talking about creating an Event Log, ... Administrators group on the local machine, or the local System account. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Is it really true that NTFS is secure?
    ... Well I look at both those Run keys; HKLM; HKCU. ... I actually have only two things which are in HKCU Run: ... >> It is the Administrator account that is enabling the user Guest. ... > if the user logging in was a domain admin. ...
    (microsoft.public.security)
  • Re: Set temp path by Policy
    ... I run on startup a batch with "reg import settemp.reg". ... but some of the reg settings were HKLM and caused the whole file to get ... > I don't remember if I tested much creating a new account that time but I ... >> I've created all the required reg settings for moving the IE and other ...
    (microsoft.public.windowsxp.embedded)