RE: Set ACL on Application and Security logs

From: Dominick Baier (db_at_die-lounge.com)
Date: 05/16/05

  • Next message: Z E: "Re: Set ACL on Application and Security logs"
    To: "'Z E'" <z.emailaccount@gmail.com>, <focus-ms@securityfocus.com>
    Date: Mon, 16 May 2005 19:22:56 +0200
    
    

    under w2k3 this is possible, read here
    http://www.leastprivilege.com/PermaLink.aspx?guid=3b88241e-fac6-40d1-98ea-c3
    465e7109f2

    -----Original Message-----
    From: Z E [mailto:z.emailaccount@gmail.com]
    Sent: Montag, 16. Mai 2005 14:45
    To: focus-ms@securityfocus.com
    Subject: Set ACL on Application and Security logs

     Is there a way to prevent users from accessing the information in the
    system and application logs? similar to the way that the security log is
    restricted?

    File system ACLs on the log files do not work. Plus, restricting the Event
    viewer and computer management MMCs through group policy does not ensure
    that users do not use command line tools to access these logs.

    Thanks for the help.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Z E: "Re: Set ACL on Application and Security logs"

    Relevant Pages

    • Re: unaccesible system event log
      ... Sophos EM Library is one part of antivirus solution for distributing ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you get ...
      (microsoft.public.windows.server.active_directory)
    • Re: The security log on this system is full
      ... Even I clear the event security logs, the error disappears during some days ... I wouldn't set to ''1'' because it will crash my server. ...
      (microsoft.public.security)
    • Re: unaccesible system event log
      ... antivirus protection Sophos to workstations. ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
      (microsoft.public.windows.server.active_directory)
    • Re: unaccesible system event log
      ... "Al Mulnick" wrote: ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
      (microsoft.public.windows.server.active_directory)
    • Re: Analyse der Security Logs (DCs)
      ... > ich suche Produkte zur Analyse von Security Logs. ... wäre MOM eine Möglichkeit. ... jedoch out-of-the-box keine Regeln für die Analyse von Security Logs, ...
      (microsoft.public.de.german.win2000.active_directory)

  • Quantcast