Re: Auditing Logon events on Windows 2003 DC

From: Andy Barkl [MVP] (abarkl_at_community.nospam)
Date: 10/19/04


Date: Tue, 19 Oct 2004 14:24:18 -0700


"rhubman16" <rhubman16@discussions.microsoft.com> wrote in message
news:45F22023-9200-42FF-B3A4-49E5B8411263@microsoft.com...
>I am trying to monitor logon failures on our domain controllers. I read
>that
> if you turn on the 'Audit Logon Events' policy on the DCs, you will get
> entries in the 500 range in the event viewer (ie. 539 account locked out).
>
> I dont get these entries I do get 675 errors but there are hundreds of
> them,
> it also enters one for bad passwords.
>
> Does anyone know what I am doing wrong?
>
> Thank you

This article lists the Account Logon events (6xx) and Audit Logon events
(5xx) which are different;
http://www.microsoft.com/technet/security/guidance/secmod128.mspx#EIAA



Relevant Pages

  • Re: Get list of users who logged into Domain Controller?
    ... need to enable "Audit logon events" I suggest you also enable "audit account ... Both of these should be enabled on the domain controller policy. ... > Networks" was missing from the Network Properties. ...
    (microsoft.public.win2000.security)
  • Re: Log-in log-out
    ... In addition to the policy already in place also enable the "Audit logon events" policy, you should then see Events 528. ... Audit account logon events will record events 680 and 681. ...
    (microsoft.public.win2000.general)
  • Windows 2003 (IIS6) security question
    ... If you enable auditing for "Audit Logon Events" or "Audit Account ... would be for a high traffic web server getting an essentail DOS attack ...
    (microsoft.public.inetserver.iis.security)
  • Re: monitor logon time
    ... Appears Audit logon events needs to be turned on also. ... The one you mention is ones the local security system authorised. ... Click on Local Policies/Audit Policies, ...
    (microsoft.public.windowsxp.general)
  • Re: Security Event log full in 30 min
    ... > Audit Account Logon Event - which is what you want. ... > Audit Logon Events should log everything, ... not the system logon events. ...
    (microsoft.public.win2000.security)