Re: No MACHINE$ inside "Audit account logon events"
- From: Meinolf Weber <meiweb(nospam)@gmx.de>
- Date: Thu, 27 Nov 2008 06:31:44 +0000 (UTC)
Hello pink0.pallino,
Account is also a computer not only a user, that's the reason that computer's are also logged. You can not filter them i think.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hi there,
just out of curiosity, my server's security eventlog is full of
events such as
User Logoff:
User Name: MYMACHINE$
Domain: NYDOMAIN
Logon ID: (0x0,0x5A8F20F)
Logon Type: 3
for event 540 and 538
this is because the "logging login/off " feature inside the "Audit
account logon events" GPO is enabled.
Is there anyway to filter out the MACHINE$ events since I just need
the user's logon/off?
thanks
a
.
- Follow-Ups:
- Re: No MACHINE$ inside "Audit account logon events"
- From: pink0.pallino
- Re: No MACHINE$ inside "Audit account logon events"
- References:
- No MACHINE$ inside "Audit account logon events"
- From: pink0.pallino
- No MACHINE$ inside "Audit account logon events"
- Prev by Date: Re: File permission problems
- Next by Date: Re: No MACHINE$ inside "Audit account logon events"
- Previous by thread: No MACHINE$ inside "Audit account logon events"
- Next by thread: Re: No MACHINE$ inside "Audit account logon events"
- Index(es):
Relevant Pages
|