Re: security event logs in DC as well ? SOS



I don't know how you are seeing duplicate events because what is recorded in
the security log is what is happening on that computer. For instance when
auditing of logon events is enabled on a computer it will show when a
computer/user attempts to access the computer either via interactive logon
or via network share such as type 3 logon. These events would not be
recorded on a domain controller. You might however see an "account logon"
event recorded on a domain controller at the sane time as you see a logon
event on a domain computer because the user is authenticating to the domain
controller. You would not however see hack attempts on the domain computer
for " local" user accounts such as the built in administrator account in the
security log of a domain controller as account logon attempts. They would
only show in the security log of the domain computer. -- Steve


"Simo Sentissi" <msentissi@xxxxxxxxxxxx> wrote in message
news:er7Ui3vbGHA.5116@xxxxxxxxxxxxxxxxxxxxxxx
hello there

I am shipping all the security and application event log from servers to a
log agregation tool and i see some duplication of events from both the
domain controlers and the normal machines.
I am wondering if I even should ship the security evetn logs to the tool
if i am already shipping the security evetns from the DCs?

I have tons of duplications anybody knows ?
any ideas ? am I missing somethings ?



.



Relevant Pages

  • Re: Audit Logon Failures
    ... > success and failure in Domain Controller Security Policy. ... > auditing of logon events for the domain computers. ... > size of your security log quite a bit from default to at least 10MB. ...
    (microsoft.public.security)
  • Re: Login Time out
    ... If the users logon to just the domain and not the local computer, ... security log will have a LOT of events in it so you may want o use the ... domain controller, do it Domain Security Policy in administative tools on ...
    (microsoft.public.win2000.security)
  • Re: Tracking unauthorized access to my computer
    ... Remote Desktop. ... The user name, logon type, and time can give you an idea who is ... Also look at your own logon events for your user account ... I would also increase the size of the security log to like ...
    (microsoft.public.security)
  • Re: Event 529 occuring 2500 times every day
    ... I am receiving this error message in my security log about 2500 ... Logon Failure: ... User Name: HSSSERVER$ ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Event 529 occuring 2500 times every day
    ... I am receiving this error message in my security log about 2500 ... Logon Failure: ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)

Quantcast