Re: Users are Unable to login due to Security log being full on XP

From: Dolemite (yomama_at_nospam.com)
Date: 06/10/03


Date: Tue, 10 Jun 2003 03:41:05 -0700


I found this article after poking around. Please make sure these directions
are followed when creating policies for XP machines in a Win2K domain.

http://support.microsoft.com/default.aspx?scid=kb;en-us;263627

Secondly, can you please include the exact and entire event log message as I
am not seeing any references to event 560 in my resources.

"Geraldo Quezada" <gquezada@primebroker.com> wrote in message
news:OAWHZ8dKDHA.2148@TK2MSFTNGP12.phx.gbl...
> The security event log on multiple XP worktation is getting filled up with
> event id 560 and once filled the user can not login. Only Administrators
> can.
>
> Object Access Auditing has been enable through a GPO (needed to conform
with
> company security standards) in the Domain. This is what causing the
failure
> audit events on the workstations.
>
> I would like to know if there is any way to allow the user login to the
> workstation after the security log gets filled without giving him/her
local
> admin rights.
>
>
>



Relevant Pages

  • Re: AspErrorsToNTLog no longer works in IIS6
    ... The security implication is that anonymous remote requests can be used to ... fill the event log and cause the server to stop responding (for very legal ... > logic for further disabling it. ... How about using the web log file? ...
    (microsoft.public.inetserver.iis)
  • Viewing Event Logs
    ... How to set event log security locally or by using Group Policy in Windows ... Descriptor Definition Language (SDDL) syntax. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AspErrorsToNTLog no longer works in IIS6
    ... Am I to assume IIS6 no longer offers a way to audit VBScript errors? ... >>when the security log is full has any relevance. ... Is event log performance significantly ... > log instead of the normal log file) was flawed from a security perspective, ...
    (microsoft.public.inetserver.iis)
  • Re: Writing to Windows Security Log
    ... UNIX syslog-the-network-protocol is that it's UDP - ... a Windows application or service ... equivalent source of bogus data into an Event Log stream ... to the>Security< Event Log are the LSA and the Event ...
    (Pen-Test)
  • Win2k3 Event Log and Security: Must choose between security and trustworthy
    ... have as well) regarding the way the EventLog.WriteEntry encounters security ... problems when to trying to create new Event Logs and new Event Log Sources. ... coding of the application developers create new sources. ... I am not entirely certain of the security impact of doing this. ...
    (microsoft.public.inetserver.iis.security)