Set ACL on Application and Security logs

From: Z E (z.emailaccount_at_gmail.com)
Date: 05/16/05

  • Next message: Kern, Tom: "RE: Set ACL on Application and Security logs"
    Date: Mon, 16 May 2005 08:45:09 -0400
    To: focus-ms@securityfocus.com
    
    

     Is there a way to prevent users from accessing the information in the
    system and application logs? similar to the way that the security log
    is restricted?

    File system ACLs on the log files do not work. Plus, restricting the
    Event viewer and computer management MMCs through group policy does
    not ensure that users do not use command line tools to access these
    logs.

    Thanks for the help.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Kern, Tom: "RE: Set ACL on Application and Security logs"

    Relevant Pages

    • RE: Set ACL on Application and Security logs
      ... There is alos a GPO for this. ... > system and application logs? ... > File system ACLs on the log files do not work. ... Plus, restricting the ...
      (Focus-Microsoft)
    • Re: Illegal access attempt - FreeBSD 5.4 Release - please advise
      ... The connection attempts are harmless, ... since they fill up the logs. ... I decided to "solve" the problem by restricting the IP range that can ...
      (freebsd-questions)
    • Re: robots.txt: Good, Bad, Ugly?
      ... Dave wrote: ... means of restricting them. ... I am examining both and may (probably more for fun than need) implement something (at least for a little while and look at the logs). ...
      (comp.os.linux.security)
    • Re: Reading Security Event Logs with Service Account
      ... the right pane will be Manage auditing and security log. ... then set that in the GPO for the OU where the servers are. ... Add the user account to that group afterwards. ... logs on Windows servers. ...
      (microsoft.public.windows.server.security)
    • Re: Authentication Failure
      ... We're on the same wavelength - I'd already saved and cleared the logs. ... There is nothing showing in the event logs on the DC. ... > administrator and clearing the security log. ...
      (microsoft.public.win2000.security)