Re: Auditing Logon Events

From: Herb Martin (news_at_LearnQuick.com)
Date: 03/10/04


Date: Wed, 10 Mar 2004 11:02:58 -0600


"Keith" <@.> wrote in message news:OOn#lxrBEHA.2628@TK2MSFTNGP11.phx.gbl...
> I have just been trying to set up auditing on my 2k DC to log every time a
> user logs onto the system. However, after 5 minutes I ended up with about
> 2000 entries in the System Log.

Account logon events will log every request to the DC for authentication;
include to "actually logon" or to access services. Even IPSec Kerberos
authentication adds to this load.

If you have a few hundred users this might not be too big a deal.

> What do I need to turn on to correctly log just logon events or have I
done
> it correctly and this is what happens?

You could log just FAILURES. (to determine if you are being attacked.)
You could log "Logon" events which are ONLY interactive logons and are
recorded at the work stations -- but then you will need to collect them all
eventually.

-- 
Herb Martin
"Keith" <@.> wrote in message news:OOn#lxrBEHA.2628@TK2MSFTNGP11.phx.gbl...
> I have just been trying to set up auditing on my 2k DC to log every time a
> user logs onto the system.  However, after 5 minutes I ended up with about
> 2000 entries in the System Log.
>
> What do I need to turn on to correctly log just logon events or have I
done
> it correctly and this is what happens?
>
> Thanks
>
>


Relevant Pages

  • Re: GPO Policy Auditing Solution
    ... within the Domain Controller's OU and enable account logon auditing in the ... enable auditing for logon events. ...
    (microsoft.public.windows.server.networking)
  • Re: Multiple 538 and 540 IDs in 2003 server Security Events Log?
    ... You may not even want to use auditing of logon events on domain ... controllers because of all the noise and instead use ... ID's appear again several times when the user logs off. ...
    (microsoft.public.windows.server.security)
  • Re: Log terminal server logins?
    ... The logon events include a logon type for ... > Not in a login skript, ... > enable auditing for all security events). ...
    (microsoft.public.win2000.security)
  • Auditing Logon Events
    ... I have just been trying to set up auditing on my 2k DC to log every time a ... user logs onto the system. ... What do I need to turn on to correctly log just logon events or have I done ...
    (microsoft.public.windows.server.active_directory)
  • Re: Bypass Traverse Checking
    ... > The odd thing is in my Event log, I see an entry granting it to a specific ... > Special privileges assigned to new logon: ... > Privileges: SeChangeNotifyPrivilege ... If you are auditing logon events for Everyone, ...
    (microsoft.public.windowsxp.security_admin)