RE: audit user logon activity

adisegna_at_siscocorp.com
Date: 10/07/04

  • Next message: David Nardoni: "RE: audit user logon activity"
    Date: Thu, 7 Oct 2004 12:43:23 -0400
    To: <cyz2000@yahoo.com>, <security-basics@securityfocus.com>
    
    

    Chang,

    Read any Windows Security guideline paper. You will get information on
    audition logon events. Check out www.nsa.gov for guide guidelines.

    Audit Logon events - This category is separate from the "Audit Account
    logon events". This category will generate a success or failure event
    when a user logs in or out of the system. Events are also generated when
    a user connects or disconnects from a system via either an interactive
    type of logon, or via a network type of logon

    Audit account logon events - this category will generate success or
    failure events whenever a domain controller receives a logon request.

    Arthur DiSegna
    Information Technology Group
    Security Identification Systems Corporation
     

    -----Original Message-----
    From: chang zhu [mailto:cyz2000@yahoo.com]
    Sent: Wednesday, October 06, 2004 3:11 PM
    To: security-basics@securityfocus.com
    Subject: audit user logon activity

    Hi, all

    I tried to find out how to find whether a user logs to
    multiple computers on the network. From MS security
    log, I can notfind anything I want to. Is there any
    windows freeutility which allows to audit a user's log
    onactivity?
    (BTW, we are in windows 2000 environment).

    Thanks,

    chang

    __________________________________________________
    Do You Yahoo!?
    Tired of spam? Yahoo! Mail has the best spam protection around
    http://mail.yahoo.com


  • Next message: David Nardoni: "RE: audit user logon activity"

    Relevant Pages

    • Re: Event Log ID 538 and 540 continous
      ... I believe the Default Domain Controller Security Settings for SBS 2003 are ... set to 'Success' for "Audit Logon Events" and "Audit Account Logon" events. ... Turning on "Audit Logon Events" may generate a large log (on my test server, ... You may be able to switch to only activating "Audit Account Logon Events" ...
      (microsoft.public.windows.server.sbs)
    • Re: Auditing Attempted Shared Folder Access
      ... NTFS auditing is controlled by enabling audit of Object Access ... Audit Acct Management ... Audit Logon Events ... Security: Everyone Full Control ...
      (microsoft.public.security)
    • Re: Event Logs/Event Viewer
      ... That works for Pro but Home has no group policy editor. ... Set both Audit account logon events & Audit logon events for Success & ...
      (microsoft.public.windowsxp.general)
    • Re: Audit: Account Logon Vs. Logon Events
      ... Audit logon events ... Policies\Audit Policy ... Determines whether to audit each instance of a user logging on, logging off, ... unchecking Success and Failure. ...
      (microsoft.public.win2000.security)
    • Re: Track abnormal restart
      ... Set both Audit account logon events & Audit logon events for Success & ...
      (microsoft.public.windowsxp.general)