Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Security Auditing

Reply
Thread Tools Display Modes

Security Auditing

 
 
Willis
Guest
Posts: n/a

 
      10-23-2009
Hello,

Does anyone here have any good suggestions for security auditing in a SMB
Server 2003 environment?

We need a record of every time a user logins, logouts or unlocks windows xp
on their local computer and preferably a central location to manage these
records.

I've been trying to use the DC security log to monitor events but it is so
tedious sorting through object and login events by every program and user
and it doesn't log when the user unlocks their windows session. It also
fills up extrememly fast. We get barely get 20 hours with a 32MB file.
There has to be a better way to manage these without spending a ton of money
on a 3rd party event manager, right?

Any help is appreciated.

Thanks,
Andrew


 
Reply With Quote
 
 
 
 
PA Bear [MS MVP]
Guest
Posts: n/a

 
      10-23-2009
[Crosspost much?]

Willis wrote:
> Hello,
>
> Does anyone here have any good suggestions for security auditing in a SMB
> Server 2003 environment?
>
> We need a record of every time a user logins, logouts or unlocks windows
> xp
> on their local computer and preferably a central location to manage these
> records.
>
> I've been trying to use the DC security log to monitor events but it is so
> tedious sorting through object and login events by every program and user
> and it doesn't log when the user unlocks their windows session. It also
> fills up extrememly fast. We get barely get 20 hours with a 32MB file.
> There has to be a better way to manage these without spending a ton of
> money
> on a 3rd party event manager, right?
>
> Any help is appreciated.
>
> Thanks,
> Andrew


 
Reply With Quote
 
PA Bear [MS MVP]
Guest
Posts: n/a

 
      10-23-2009
[Pointless & excessive crossposting eliminated]

Got Google?

cf. http://articles.techrepublic.com.com...1-6074792.html

cf.
http://www.trainsignal.com/Windows-S...ining-P17.aspx


Willis wrote:
> Hello,
>
> Does anyone here have any good suggestions for security auditing in a SMB
> Server 2003 environment?
>
> We need a record of every time a user logins, logouts or unlocks windows
> xp
> on their local computer and preferably a central location to manage these
> records.
>
> I've been trying to use the DC security log to monitor events but it is so
> tedious sorting through object and login events by every program and user
> and it doesn't log when the user unlocks their windows session. It also
> fills up extrememly fast. We get barely get 20 hours with a 32MB file.
> There has to be a better way to manage these without spending a ton of
> money
> on a 3rd party event manager, right?
>
> Any help is appreciated.
>
> Thanks,
> Andrew


 
Reply With Quote
 
JohnB
Guest
Posts: n/a

 
      10-24-2009
> Got Google?

Sometimes this helps them remember:
http://tinyurl.com/yf7rmb5





>
> Got Google?
>






> cf. http://articles.techrepublic.com.com...1-6074792.html
>
> cf.
> http://www.trainsignal.com/Windows-S...ining-P17.aspx
>
>


 
Reply With Quote
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      10-26-2009
If you are looking at the growth on the dc and you have a lot of clients,
that growth is relatively normal. We ended up purchasing a third party
product and outputting it to a SQL Server DB that stay at about 8 gb for 30
days of logs. The third party product does allow us to par back with logs
we save but we just keep them all. We use Event Sentry.

You can log the activity on a single machine but unless you are interested
in a specific machine this would be a bad idea.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Willis" <> wrote in message
news:...
> Hello,
>
> Does anyone here have any good suggestions for security auditing in a SMB
> Server 2003 environment?
>
> We need a record of every time a user logins, logouts or unlocks windows
> xp on their local computer and preferably a central location to manage
> these records.
>
> I've been trying to use the DC security log to monitor events but it is so
> tedious sorting through object and login events by every program and user
> and it doesn't log when the user unlocks their windows session. It also
> fills up extrememly fast. We get barely get 20 hours with a 32MB file.
> There has to be a better way to manage these without spending a ton of
> money on a 3rd party event manager, right?
>
> Any help is appreciated.
>
> Thanks,
> Andrew
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Auditing Willis Active Directory 2 10-26-2009 11:22 AM
Security Auditing Willis Windows Server 4 10-26-2009 11:22 AM
Files on D from XP have strange user under Security. Trond Windows Vista Administration 6 03-04-2007 02:57 AM
Files on D: from XP have strange user under Security. Trond Windows Vista Administration 0 02-25-2007 12:49 AM
set security level back to the same as XP possible ???? m j o Windows Vista Installation 1 02-14-2007 02:14 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59