Re: Auditing Logon Events

From: Steven L Umbach (sumbach_at_nospam-ameritech.net)
Date: 03/12/04


Date: Fri, 12 Mar 2004 14:42:14 GMT

That is normal to see. I believe a lot of those events are computer account
related. For a domain controller you may want to audit account logon events
instead and maybe just failures for logon events. --- Steve

"help" <help@help.co.uk> wrote in message
news:c2shp4$34h$1@sparta.btinternet.com...
> At the moment, on a Windows 2000 with SP4 server that is a Domain
> Controller, if I have the following policies set with the DC Security
> Policy:
> Audit Account Logon Events: None
> Audit Logon Events: Success+Failures
>
> then I get mulitple events logged for each instance of log-on and log-off
>
> To be precise, for logons, I get Event IDs:
> 528 Successful Logon
> 515 A trusted logon process has registered with the Local Security
> Authority. This logon process will be trusted to submit logon requests.
> 540 Successful Network Logon: TWICE
>
> For Logoffs
> 538 Successful Logoffs: multiple entries
>
>



Relevant Pages

  • Re: security auditing
    ... I enabled 'Audit account logon events' and 'Audit logon events' ... Policies/Audit Policy for a policy that covers about 15 users to test it. ... If you want to log all domain logons, go create the "Audit account logon ...
    (microsoft.public.windows.group_policy)
  • Re: security auditing
    ... I enabled 'Audit account logon events' and 'Audit logon events' under Computer Configuration-Windows Settings-Security Settings-Local Policies/Audit Policy for a policy that covers about 15 users to test it. ...
    (microsoft.public.windows.group_policy)
  • Re: Auditing Workstation logons from DC
    ... This is "Logon event" ... > I am trying to see workstation interactive logins in the Windows 2003 DC ... > Settings for Audit account logon to Success and Audit logon events to ... I have Domain Controller Settings to audit account logon to ...
    (microsoft.public.windows.server.security)
  • audit logon failure
    ... I want to track account logon failures in a w2k domain. ... domain policy the 'audit account logon events' and 'audit logon events' on ...
    (microsoft.public.win2000.security)
  • Re: Auditing User logon/logoff events.
    ... u say in the document like i enabled "Account logon events" only in domain ... Then i am getting 672,673 event ids in my domain controllers event viewer. ... can see this log in domain controller security log. ...
    (microsoft.public.win2000.security)