Re: Multiple 538 and 540 ID's in 2003 server Security Events Log?



It is normal to see many logon/logoff events in the security log of domain
controllers when auditing of logon events is enabled and a lot of that
activity is for authentication traffic and accessing sysvol for Group
Policy. You may not even want to use auditing of logon events on domain
controllers [or audit failure only]because of all the noise and instead use
auditing of account logon events though that will NOT show when a user logs
off "their domain" computer nor will "logon" events from the domain
controller. To get more accurate information for logoff you need to enable
auditing of "logon" events on the domain computers and then get the logon
and logoff event from the local security log of the domain computer.

Steve


"Reluctant Sys-Admin" <ReluctantSysAdmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:06D890FE-CF4D-4151-BFED-80DE714D8EF5@xxxxxxxxxxxxxxxx
I have a 2003 Server domain controller and XP workstations. I am trying to
audit when domain users log on and off the domain for the day.

There seem to be multiple 538(successful logoff) and 540(successful logon)
event ID's in the Security Events Log for each user when they log on.
Both
ID's appear again several times when the user logs off. Sometimes the
ID's
appear a few minutes apart for the same actual log on/off event, which
makes
it hard to tell when the event actually occurred. Is there a better way
to
tell conclusively exactly when a user logs on/off the domain?

Thanks!



.



Relevant Pages

  • Re: Authentication Auditing
    ... > only show in the security log of the domain computer itself - not the ... > it indeed does show that auditing of logon events is enabled for success ... It is enabled but the effective setting dispalys as "No Auditing". ...
    (microsoft.public.win2000.security)
  • Re: Authentication Auditing
    ... What may be happening is that another Group Policy has auditing defined for ... logon events such as at the Organizational Unit Level. ... see what it is for auditing and change it to suit your needs. ... >> Then try clearing the current security log to make sure it is not full ...
    (microsoft.public.win2000.security)
  • Re: Auditing Logon Events
    ... > I have just been trying to set up auditing on my 2k DC to log every time a ... > user logs onto the system. ... Account logon events will log every request to the DC for authentication; ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote Desktop auditing
    ... XP Pro has the same auditing capabilities as Windows 2003 Server other than ... You would want to enable auditing of ... account logon events and maybe logon events in Local Security Policy. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Need logon and Logoff data for 30 days
    ... Auditing of account logon events alone will not show when a user logs off. ... You would need to enable auditing of logon events [or just use logon events ...
    (microsoft.public.security)