Re: event logs

From: Alan Levy (levy@nospaminteraccess.com)
Date: 08/21/02


From: "Alan Levy" <levy@nospaminteraccess.com>
Date: Wed, 21 Aug 2002 15:53:09 -0500

Dave:

 This is by design. The whole idea is to prevent a non-administrator from
making an action on a system that need to be logged but cannot because the
log is full. The OS prevents non-admins from logon. An Administrator can
login to clear the log or reset the logging option. That is why when you
give someone administrator access he/she can login. I would also look at
the following Knowledge Base Article, at http:\\support.microsoft.com once
there simply search either the article title or PSS number for more
information
 STOP 0xC0000244 When Security Log Full [Q232564]

Article last modified on 08-10-2001

.
Good luck,
alan

--
Microsoft MVP
"Dave B" <dave@omni-med.com> wrote in message
news:5ed101c24953$06732d80$a5e62ecf@tkmsftngxa07...
> Windows XP Pro computer in a workgroup. I have set the
> option to overwrite events older than 7 days when the
> event log is full. However, when a standard user tries to
> log onto the computer and the event log is full, i
> receive the error "the security event log is full. Only
> administrators can open a session to fix this problem. I
> have verified the local system policy and can not find
> the problem. I feel it is a security problem because if I
> give the user admin rights, there is no problem.
> Dave


Relevant Pages

  • Re: Access is denied
    ... Event ID 577 appears repeatedly in the security event log of your Windows ... Troubleshooting Windows XP ... > The administrator and administrators have full control of the objects in ...
    (microsoft.public.windowsxp.general)
  • [NT] A Full Event Log Does Not Send Administrative Alerts
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A security vulnerability in Microsoft's Windows operating system causes it ... to not inform the administrator whenever the Event Log has been filled ... hide his tracks by filling up the Event Log prior to attacking the system. ...
    (Securiteam)
  • Security Event Log
    ... I am tring to subscribe to the "Security" event log but I get access denied ... When I run my code as administrator it works fine but when I impersonate ... What I am trying to accomplish is to get logon, logoff, logon failure ...
    (microsoft.public.platformsdk.security)
  • Lock down Event Logs?
    ... How can an administrator prevent non-administrator view access ... to the event logs? ... I want only a DA to see the App/Sys/NTFRS/NTDS/DNS & of course security ...
    (microsoft.public.security)
  • Lock down Event Logs?
    ... How can an administrator prevent non-administrator view access ... to the event logs? ... I want only a DA to see the App/Sys/NTFRS/NTDS/DNS & of course security ...
    (microsoft.public.windowsxp.security_admin)