Lock down Event Logs?

From: - (-_at_-.com)
Date: 07/24/04


Date: Fri, 23 Jul 2004 18:27:40 -0400

I know this question has been asked before but I haven't been able to find
an answer. How can an administrator prevent non-administrator view access
to the event logs? The policy only references preventing the guest account.
I want only a DA to see the App/Sys/NTFRS/NTDS/DNS & of course security
event logs. The security event logs are truly locked down to only
administrators, but how can one do the same thing for the other event logs.
Seeing the even the non-security logs is in itself a security breach.

Do I have to use NTFS ACL's on the files? Is that the only way?



Relevant Pages

  • Re: User accounts disabled automatically by administrator?!
    ... Accounts will not disable themselves. ... Check the event logs in your dc's for event id 629. ... user accounts disabled automatically by administrator. ... I feared domain ...
    (microsoft.public.windows.server.active_directory)
  • More Event Viewer problems!
    ... Since switching XP-PRO to look like "Classic" ... event logs from Administrator and other Accounts that are ...
    (microsoft.public.windowsxp.security_admin)
  • event log shows logons when there were none
    ... We have a win2k domain with 5 workstations. ... In the event logs of the workstations I can see administrator and some ... username logoff events without logon events. ...
    (microsoft.public.win2000.security)
  • Access to Event Logs Denied
    ... After performing a user and group migration between an NT4 Domain to a new ... 2K3 Domain this morning I now find the Administrator is no longer allowed ... the source domain this works fine and has access to all of the event logs. ... How can I re-instate the administrators account ...
    (microsoft.public.windows.server.migration)
  • Lock down Event Logs?
    ... How can an administrator prevent non-administrator view access ... to the event logs? ... I want only a DA to see the App/Sys/NTFRS/NTDS/DNS & of course security ...
    (microsoft.public.windowsxp.security_admin)