RE: Windows Event Logs
From: Brad Judy (judy_at_colorado.edu)
Date: 06/20/03
- Previous message: Cushing, David: "RE: Filtering DHCP Assignments by MAC Address"
- In reply to: Floyd Russell: "Windows Event Logs"
- Next in thread: Levinson, Karl: "RE: Windows Event Logs"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "'Floyd Russell'" <floyd@neospire.net>, <focus-ms@securityfocus.com> Date: Fri, 20 Jun 2003 08:33:59 -0600
The lack of IP logging on NTLM authentications has been the source of
frustration for many admins. However, this feature has finally been
added to Windows 2003 Server - only seven years after the release of
Windows NT 4. :)
Brad Judy
Information Technology Services
University of Colorado at Boulder
> -----Original Message-----
> From: Floyd Russell [mailto:floyd@neospire.net]
> Sent: Thursday, June 19, 2003 12:28 PM
> To: focus-ms@securityfocus.com
> Subject: Windows Event Logs
>
>
> In my years of admining windows servers the event logs have
> always been frustratingly incomplete. This is especially true
> with the Security logs. For example if an attempted logon
> fails, it records the event, but seeminly nothing else of
> importance like an IP. Are there any tools out there that
> either allow admins a finer control over what activities
> happen on the host or any that can pull such information from
> the event logs?
>
> Thanks,
> Floyd R.
>
>
> --------------------------------------------------------------
> ---------------
> --------------------------------------------------------------
> ----------------
>
-----------------------------------------------------------------------------
------------------------------------------------------------------------------
- Previous message: Cushing, David: "RE: Filtering DHCP Assignments by MAC Address"
- In reply to: Floyd Russell: "Windows Event Logs"
- Next in thread: Levinson, Karl: "RE: Windows Event Logs"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|