Auditing Logons and Logoffs
- From: barrycuda72@xxxxxxxxx
- Date: 9 Mar 2006 08:55:56 -0800
I am sure that this has been mentioned hundred of times but still I
need some help in understanding a few things, so please bear with me.
Have an Win2k domain 3 DC's 800 Users.
All computers are members of the domain and they logon as a domain\user
I have enabled auditing on the Domain controllers ou to audit logon
events for success and failure. I do not have Audit account logon
events enabled.
I have an event log program to centralize all of my security logs into
1 mssql server.
Now the real question. What is actually getting logged?
Here are examples of what I would like to see in the log.
1.User comes to work 8:00am logs into their workstation as a
domain\user
Will I see an event in the DC security log? What will it be?
2. User goes to get coffee locks computer?
Will I see an event in the DC security log? What will it be?
3. A users screen saver kicks in that requires a password to unlock
Will I see an event in the DC security log? What will it be?
4. User accesses a file\folder on a windows share
Will I see an event in the DC security log? What will it be?
5. User goes home for the day logs off of system
Will I see an event in the DC security log? What will it be?
.
- Follow-Ups:
- Re: Auditing Logons and Logoffs
- From: Steven L Umbach
- Re: Auditing Logons and Logoffs
- Prev by Date: Export Domain Account to another Server
- Next by Date: Re: Export Domain Account to another Server
- Previous by thread: Export Domain Account to another Server
- Next by thread: Re: Auditing Logons and Logoffs
- Index(es):
Relevant Pages
|
Loading