Re: Auditing Clear All Events in the Event Viewer

From: Eric Fitzgerald [MSFT] (ericf_at_online.microsoft.com)
Date: 06/28/03


Date: Fri, 27 Jun 2003 18:33:58 -0700


No, this feature is specific to the security log.

You can accomplish something similar by auditing for deletes in the
directory:
%windir%\system32\config

In this case, event 560 would be logged in the security log whenver a log
was cleared. However it's not nearly as clear and more work to find.

Info on how to set up file auditing is in the help and in the Knowledge
Base.

Sorry Linda,

Eric

"Linda" <lindapens@earthlink.net> wrote in message
news:0d6501c33670$7a34e5f0$a601280a@phx.gbl...
> I'm looking for information about auditing clear all
> events when this is done on the application log. When I
> clear all events on the security log the event is audited
> and becomes the first event in the security log after it
> is cleared. I would also like to do this for the
> Application log. Is this possible and if so how? Thanks



Relevant Pages

  • Re: Authentication Auditing
    ... > only show in the security log of the domain computer itself - not the ... > it indeed does show that auditing of logon events is enabled for success ... It is enabled but the effective setting dispalys as "No Auditing". ...
    (microsoft.public.win2000.security)
  • Re: Audit Failures/READ_CONTROL SYNCHRONIZE
    ... You're auditing File and Object Access; you've enabled Auditing on the files ... and you're complaining about audit events ... You can't mask events out of the security log in Event Viewer. ... > Client Domain: HEX21 ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Monitor User Remotely.
    ... activity, auditing of process tracking on ... remotely via administrator share, and folder files have creation timestamps ... he can clear the security log. ... > Is there any way we can remotely monitor him, ...
    (microsoft.public.win2000.security)
  • Re: Auditing file changes
    ... You might want to have them check who is the owner of the file. ... object access in Local Security Policy on the computer and enable auditing ... on the folder or file they need to track. ... security log size will need to be increased substantially to probably at ...
    (microsoft.public.win2000.security)
  • Re: Cannot see audit events in security log
    ... I tried turning auditing off and on again after converting to NTFS in ... > If you enabled auditing of object access then you should see events in the ... > the size of the security log quite a bit and clear the log first. ... >> trying to establish auditing on a folder and its contents. ...
    (microsoft.public.win2000.security)