Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Auditing events for Security Monitoring

Reply
Thread Tools Display Modes

Auditing events for Security Monitoring

 
 
Venkatesh
Guest
Posts: n/a

 
      07-22-2009
Hi there,

In a Windows Server 2003, how can we monitor the following events:

* All actions taken by any individual with administrative privileges.
* Initialization of the audit logs.
* Creation and deletion of system-level objects e.g DLL and critical EXE
files.
* Service Account Authentication

Please let me know what needs to be turned-on in GPEdit.msc. Also, if you
can share the corresponding event ID numbers it would be great.

Thank,

 
Reply With Quote
 
 
 
 
Anthony [MVP]
Guest
Posts: n/a

 
      07-23-2009
Venkatesh,
You can achieve that by turning on Success and Failure auditing for all
classes.
I think your problem will be rather how to analyse the data to make any
sense of it,
Anthony,
http://www.airdesk.com


"Venkatesh" <> wrote in message
news:0B2D84C6-A0B7-4D5A-8A85-...
> Hi there,
>
> In a Windows Server 2003, how can we monitor the following events:
>
> * All actions taken by any individual with administrative privileges.
> * Initialization of the audit logs.
> * Creation and deletion of system-level objects e.g DLL and critical EXE
> files.
> * Service Account Authentication
>
> Please let me know what needs to be turned-on in GPEdit.msc. Also, if you
> can share the corresponding event ID numbers it would be great.
>
> Thank,
>

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
AD Auditing and 565 Events Mike55 Active Directory 4 09-09-2008 09:29 PM
AD Auditing events Civic Active Directory 0 12-04-2007 09:28 PM
Re: Auditing Security Events Myweb Server Security 0 05-13-2007 07:27 PM
Re: ADAM auditing - EventID 2521 unable to initialize auditing security system Lee Flight Active Directory 0 04-06-2005 03:17 PM
Limiting Security Auditing Events Al Christoph Windows Small Business Server 1 04-15-2004 07:29 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59