Re: securing the event log

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/09/04


Date: Thu, 08 Jan 2004 23:04:58 GMT

There is a user right assignment for managing auditing and security log that would
need to include appropriate membership. Also check ntfs permissions on the .evt files
and eventvwr.msc file. it could also be configured as restricted in Group Policy
under user configuration/administrative templates/Windows components/MMC/restricted
and permitted snapins. Also see KB linK below if none of that helps. --- Steve

http://support.microsoft.com/?kbid=172156

"Mike Campbell" <mac57@OPTONLINE.NET> wrote in message
news:016701c3d60f$0a55e240$a301280a@phx.gbl...
> I have a peer to peer network with an XP pro workstation
> that has the event log locked against everyone including
> the local administrator account. I have searched thru the
> local security policy & the local group policy. I cannot
> find any reference to locking out the event log. Any
> ideas?



Relevant Pages

  • RE: How do I find out who disabled an account in AD?
    ... We have "Audit account management" set to "success,failure. ... "audit directory service object" in our AD group policy. ... My question is what do I search for in the security log? ...
    (microsoft.public.security)
  • Re: Security Log Question & Hotfix?
    ... Or are the properties being set in Group Policy perhaps? ... Anthony, http://www.airdesk.co.uk ... I've set up my security log to overwrite events as needed, ...
    (microsoft.public.windows.server.general)
  • Security Log and Group Policy
    ... I need to change the setting under security log to "overwrite as needed" thru ... group policy. ... Is there a registry key or an actual setting that can ...
    (microsoft.public.win2000.group_policy)
  • Multiple Event ID 676 in Security Log
    ... Controller security log whenever a user forgets to logoff from the domain. ... Group Policy is enabled to "force logoff" when a user's logon time expires. ...
    (microsoft.public.win2000.security)

Loading