Re: Auditing Successful Logins

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 06/01/05


Date: Tue, 31 May 2005 18:47:58 -0500

You can not audit selectively for account logon or logon events. The logs
are sorted by time and you can use tools like Event Comb to make searching
through the security logs much easier. There are free third party command
line tools that allow you to dump event logs to meet certain criteria such
as PsLogList. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;308471 --- Event
Comb
http://www.sysinternals.com/ntw2k/freeware/psloglist.shtml
http://www.microsoft.com/technet/scriptcenter/scripts/logs/eventlog/default.mspx
 -- vbscipts for managing logs

"IanBHendry" <IanBHendry@discussions.microsoft.com> wrote in message
news:1874BD1C-A37A-40B4-BCB5-F45FBD475A2B@microsoft.com...
>1 of our managers wants to know when (and which) employees logon before
>8a.m.
> Can the logs be set to only record successful logons for a given time
> period? I don't want to log all successful logons - - way too much data
> to
> soft through.



Relevant Pages

  • Re: tracking user log on | log off
    ... Account Logon auditing is enabled in the DDCP ... Terminal Server environment...pretty much everyone uses Terminal Server all day long....Account Logon auditing is enabled via GPO linked to the OU in which the TS Boxes reside... ... Security Logs increased to 256MB on the TS boxes as well. ... This specific client likes this reporting/monitoring stuff....all kinds of requests for this type of stuff. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Hacking attempts?
    ... Windows logs logon type 3 in most cases when you access a computer from elsewhere on the network. ... One of the most common sources of logon events with logon type 3 is connections to shared folders or printers. ... You can use the IIS logs to track down the ip addressthat are attempting unauthorized login. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help
    ... In an Active Directory setup I use logon and logoff scripts that log the ... Use the Event logs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Question About Auditing
    ... domain account the workstation registers a logon event and the DC an Account ... >> you log at a DC it is a Account logon. ... > event and the logon event is tagged in the security logs. ...
    (microsoft.public.cert.exam.mcse)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... wired LAN and I was wondering if the logins were coming through that. ... Switch on SMTP logging and in the logs you will find the IP to block if you ... Logon Failure: ... Caller User Name: SERVER01$ ...
    (microsoft.public.windows.server.sbs)

Quantcast