Re: Auditing Logon events on Windows 2003 DC

From: rhubman16 (rhubman16_at_discussions.microsoft.com)
Date: 10/20/04


Date: Wed, 20 Oct 2004 05:19:07 -0700

I have read that article before, the problem is the Audit Logon events (5xx)
are not writing to the domain controller.

"Andy Barkl [MVP]" wrote:

> "rhubman16" <rhubman16@discussions.microsoft.com> wrote in message
> news:45F22023-9200-42FF-B3A4-49E5B8411263@microsoft.com...
> >I am trying to monitor logon failures on our domain controllers. I read
> >that
> > if you turn on the 'Audit Logon Events' policy on the DCs, you will get
> > entries in the 500 range in the event viewer (ie. 539 account locked out).
> >
> > I dont get these entries I do get 675 errors but there are hundreds of
> > them,
> > it also enters one for bad passwords.
> >
> > Does anyone know what I am doing wrong?
> >
> > Thank you
>
> This article lists the Account Logon events (6xx) and Audit Logon events
> (5xx) which are different;
> http://www.microsoft.com/technet/security/guidance/secmod128.mspx#EIAA
>
>
>



Relevant Pages

  • Re: Get list of users who logged into Domain Controller?
    ... need to enable "Audit logon events" I suggest you also enable "audit account ... Both of these should be enabled on the domain controller policy. ... > Networks" was missing from the Network Properties. ...
    (microsoft.public.win2000.security)
  • Events: Logon vs Account Logon
    ... Aren't "account logon events" going to happen on DC? ... Which event category will you audit on the domain controller to gather the necessary information? ...
    (microsoft.public.cert.exam.mcsa)
  • Re: Auditing Logon Events
    ... Logon events will generate a lot of activity as it also records computer accounts ... logging on to the domain controller. ... > have tried turning on Audit Logon Event on the Group ...
    (microsoft.public.win2000.security)
  • Re: security log anomolies
    ... > have both account logon and logon events enabled for success and failure. ... > overriding Local Security Policy. ... > controllers in particular as Domain Controller Security Policy will override ...
    (microsoft.public.win2000.security)
  • Re: security log anomolies
    ... >> have both account logon and logon events enabled for success and failure. ... >> this is a domain controller, auditing of account logons would be most ... >> settings in Local Security Policy is what the actual applied policy is to ...
    (microsoft.public.win2000.security)

Loading