Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Eventlogging 6.0, service stop/starts, who dunnit

Reply
Thread Tools Display Modes

Re: Eventlogging 6.0, service stop/starts, who dunnit

 
 
Step
Guest
Posts: n/a

 
      04-29-2010
I'm having the same issue - Has anyone found a fix?

"Craig Williams" wrote:

> On Jan 28, 1:35 pm, Craig Williams <csw...@gmail.com> wrote:
> > In the 2003/XP days I'm used to seeing events 7035 AND 7036 in the
> > system log when someone stops or starts a service.
> > 7035 reported who sent the Stop/Start Control
> > 7036 reported the state of the service after that control command
> >
> > Event Type: Information
> > Event Source: Service Control Manager
> > Event Category: None
> > Event ID: 7035
> > Date: 1/27/2010
> > Time: 10:39:03 AM
> > User: ACME\csw1 <====== INFO I NEED
> > Computer: ILCH-68889
> > Description:
> > The Telnet service was successfully sent a start control.
> >
> > Event Type: Information
> > Event Source: Service Control Manager
> > Event Category: None
> > Event ID: 7036
> > Date: 1/27/2010
> > Time: 10:39:03 AM
> > User: N/A
> > Computer: ILCH-68889
> > Description:
> > The Telnet service entered the running state.
> >
> > The problem I'm having with Server 2008 is that it ONLY records a 7036
> > and I can't tell WHO did it because the 7035 is missing. I also
> > reviewed the security log on 2008, but was not able to find a
> > correlating event there to identify the who. How do you determine the
> > WHO did it under 2008?
> > Thanks in advance
> >
> > Log Name: System
> > Source: Service Control Manager
> > Date: 1/27/2010 3:10:58 PM
> > Event ID: 7036
> > Task Category: None
> > Level: Information
> > Keywords: Classic
> > User: N/A
> > Computer: Craig2008.acme.com
> > Description:
> > The World Wide Web Publishing Service service entered the running
> > state.
> > Event Xml:
> > <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> > <System>
> > <Provider Name="Service Control Manager" Guid="{555908D1-
> > A6D7-4695-8E1E-26931D2012F4}" EventSourceName="Service Control
> > Manager" />
> > <EventID Qualifiers="16384">7036</EventID>
> > <Version>0</Version>
> > <Level>4</Level>
> > <Task>0</Task>
> > <Opcode>0</Opcode>
> > <Keywords>0x80000000000000</Keywords>
> > <TimeCreated SystemTime="2010-01-27T21:10:58.000Z" />
> > <EventRecordID>39744</EventRecordID>
> > <Correlation />
> > <Execution ProcessID="0" ThreadID="0" />
> > <Channel>System</Channel>
> > <Computer>Craig2008.acme.com</Computer>
> > <Security />
> > </System>
> > <EventData>
> > <Data Name="param1">World Wide Web Publishing Service</Data>
> > <Data Name="param2">running</Data>
> > </EventData>
> > </Event>

>
> Is there really no one that knows how to determine the user who stops/
> starts a service? MVPs?
> .
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Server 4 03-24-2010 09:19 PM
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Small Business Server 3 03-24-2010 09:19 PM
My documents opens at start up (after downloading RAR) psu027 Windows Vista Security 3 01-26-2010 03:49 AM
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM
Failed to initialize WU client: 0x8007277a Venkata Sadineni Windows Update 4 11-10-2009 06:28 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59