Security Event Log
- From: "Jos Scherders" <thrower@xxxxxxx>
- Date: Fri, 16 Mar 2007 21:26:22 +0100
Hi all,
I am tring to subscribe to the "Security" event log but I get access denied
errors.
When I run my code as administrator it works fine but when I impersonate
that same account it stops working. It seems like the access checks
performed by the event logger are only done against the process token and
not the impersonating token.
Can anyone conform this or provide an alternative solution ?
What I am trying to accomplish is to get logon, logoff, logon failure
notification so they can be sent to a special audit server but the process
that does this does not run as administrator (on purpose).
Thanks for any help.
Jos.
.
Relevant Pages
- Re: Access is denied
... Event ID 577 appears repeatedly in the security event log of your Windows ... Troubleshooting Windows XP ... > The administrator and administrators have full control of the objects in ... (microsoft.public.windowsxp.general) - [NT] A Full Event Log Does Not Send Administrative Alerts
... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A security vulnerability in Microsoft's Windows operating system causes it ... to not inform the administrator whenever the Event Log has been filled ... hide his tracks by filling up the Event Log prior to attacking the system. ... (Securiteam) - Re: event logs
... The whole idea is to prevent a non-administrator from ... give someone administrator access he/she can login. ... However, when a standard user tries to> log onto the computer and the event log is full, i> receive the error "the security event log is full. ... (microsoft.public.windowsxp.security_admin) - SBS Security event log
... I have received quite a few of these entries in my Event Log under security, ... a second entry also listed that is showing up regarding exchange. ... Logon Failure: ... (microsoft.public.windows.server.sbs) - Re: Security Log Event 529
... respectively being DOMAIN and WORKSTATION NAME as seen in the event log ... The user is ALWAYS administrator. ... system is listed as the Domain and Workstation Name. ... Microsoft Certified Trainer ... (microsoft.public.windows.server.sbs) |
|