Re: Subject: Security Event Log reading by Domain Users

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 07/28/04


Date: Wed, 28 Jul 2004 17:36:36 -0400

You are running the process directly on the server itself that you are reading
logs for? Then you just need to look at your perms on the eventlog section of
the registry and system32 and make sure the ID running the process has access.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Gera wrote:
>>You can try making it so that the process can read the event log section of the registry on that
> 
> machine.
> Could you explain how to achieve this? I mean, that we be able to use a Log Parser?
> 
> 
>>That may work, alternatively you may have to do that
>>AND open it up so the remote process can get to %SystemRoot%\System32 on the
>>remote machine.
> 
> We do not need to run Log Parser remotely, only locally.
> If it is possible fot you, please explain further, how could I let access to LogParser to registry
> and so on to make it work normally without admin rights.
> 
> 
> Thanks a lot,
> Gera, MCSE
> MGBaltic
> 
> 
> "Joe Richards [MVP]" <humorexpress@hotmail.com> wrote in message
> news:u0JVaYdaEHA.2576@TK2MSFTNGP10.phx.gbl...
> 
>>Ah.
>>
>>You can try making it so that the process can read the event log section of the
>>registry on that machine. That may work, alternatively you may have to do that
>>AND open it up so the remote process can get to %SystemRoot%\System32 on the
>>remote machine.
>>
>>
>>--
>>Joe Richards Microsoft MVP Windows Server Directory Services
>>www.joeware.net
>>
>>
>>
>>Gera wrote:
>>
>>>Thanks for repsonse.
>>>The point is, our "program" is a SQL script run trough Microsoft Log Parser.
>>>Is it possible to solve the problem in this case (using MS LP and any Windows settings)
>>>or we will need to rewrite an app in C++ using WinAPI functions?
>>>
>>>
>>>Thanks,
> 
> 
> 


Relevant Pages

  • Re: ADAM connecting to incorrect server
    ... I think you need to run a network sniff/trace to get a packet dump ... If ADAM is doing it, ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Generate NT Events
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... values (warning as its severity) then how can I generate the events? ...
    (microsoft.public.win32.programmer.kernel)
  • Re: Generate NT Events
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Editionwww.joeware.net ... values (warning as its severity) then how can I generate the events? ...
    (microsoft.public.win32.programmer.kernel)
  • Re: is the AD LDAP interface domain trust aware?
    ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Large numbers of Users in an OU
    ... Your CPU spike is likely from running ADUC on the DC, ... The former is done with a couple very lightweight LDAP calls, the latter requires SMB communications with is extremely heavy next to LDAP. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)