Re: Security event logs



Not much you can do.

If you are auditing what you want/need, the size is what you get.
AFAIK there is no way to say "Audit logon success and failure,
but only for accounts not of form *"$" or form "Svc*" "
If you can get that many days into that size log you are doing well.

The only real choices are to reduce what is logged, or to use a
form of log shipping/archiving and reduce the volume at the
archive.

"Bill C" <Bill C@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:468B215A-C86E-4AEB-AEFC-737E0F131EDF@xxxxxxxxxxxxxxxx
This might not be exactly the correct place to ask this question, however
it
is with the GPO where one controls auditing.

I would like to know how to "best" setup security auditing without having
Windows put tens thousand plus entries per day into the security log. I
want to monitor user logon, account management, policy changes and system
events. The last the aren't a major issue however, user logon is throwing
thousands of records with the majority being internal system related.

I would like a manageable security event log not 130+ MB file with 300,00+
entries that covers 45 days. I realize I can limit size and number of
days,
the real issue is 10000+ entries daily.


.



Relevant Pages

  • Re: track user logons
    ... including user actions such as logging on and logging off, and the success and failure of key ... Before you enable auditing, it will be important for you to define exactly ... For example, if you decide to audit account logon sessions, you need to consider what the information ... Your security administrators group might be interested in logging failed logon events ...
    (microsoft.public.windowsxp.security_admin)
  • your account is configured to prevent you from using this computer
    ... did manage to clear the security file and limit my ... >there is no group in the Deny local logon user right that ... >has as a member the account. ... >If in the Auditing policies you have login events being ...
    (microsoft.public.windowsxp.security_admin)
  • Stop auditing please
    ... We had a security issue a few weeks back and I enabled audits on the network ... I was auditing logon/logoff and all file or folder deletions. ... more entries per minute. ... Since hexadecimal security codes mean nothing to me, ...
    (microsoft.public.win2000.security)
  • Re: Anonymous Logons
    ... My server's security log has several entries for an anonymous logon. ... Event Type: Success Audit ...
    (microsoft.public.win2000.security)
  • Re: your account is configured to prevent you from using this computer
    ... did manage to clear the security file and limit my ... >there is no group in the Deny local logon user right that ... >has as a member the account. ... >If in the Auditing policies you have login events being ...
    (microsoft.public.windowsxp.security_admin)