Re: Audit shutdown



If you have not done so yet try auditing privilege use for success and then
look for privilege use for shut down the system event [SeShutdownPrivilege
for event 577 maybe] at the time that the operating system shuts down. Also
look for type 3 logons at a time just before the operating system shuts
down. It could also be a hardware or line voltage problem or the operating
system could be configured to reboot at system failure though you can
configure that an events be written to the system log when that happens in
system properties/advanced - startup and recovery. --- Steve



"TIwang" <TIwang@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:802CC6CD-FCFC-4FB9-862B-E7FEEB5972E3@xxxxxxxxxxxxxxxx
hi out there

We have a windows 2000 sp4 server which from time to time is being
rebooted
- I wan't to track who or what is rebooting the server. I have tried to
enable auditing on several objects and events which I expect could give me
the right information - but until now without succes - how do I enable
auditing for shutdown and which event do I need to look for ?

best regards /thomas iwang


.



Relevant Pages

  • RE: Auditing a reboot
    ... I wonder if auditing "priviledge use" would give you what you need.. ... Subject: Auditing a reboot ... > world's premier event for IT and network security experts. ... Training features 6 hand-on courses on May 12-13 taught by professionals. ...
    (Focus-Microsoft)
  • RE: Auditing a reboot
    ... If you use success auditing for loggons and logoffs you can infer the rebooting user from the the security log. ... > I would really like to know who initiated the reboot. ... >> world's premier event for IT and network security experts. ... Training features 6 hand-on courses on May 12-13 taught by professionals. ...
    (Focus-Microsoft)
  • RE: Auditing a reboot
    ... This is how I will have to go about it then, since I don't have Windows 2003 ... Subject: Auditing a reboot ... If you use success auditing for loggons and logoffs you can infer the ... >> world's premier event for IT and network security experts. ...
    (Focus-Microsoft)
  • [Summary] audit woes
    ... "error behind keyboard" or the ID-ten-T error. ... clip off part of the /etc/system file which broke this. ... > My auditing no longer works. ... > The ironic thing is that this started after the last reboot. ...
    (SunManagers)
  • RE: Auditing a reboot
    ... Subject: Auditing a reboot ... > Subject: Auditing a reboot ... > sales pitches. ... Deadline for the best rates is April 25. ...
    (Focus-Microsoft)