Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Security Event Logs being cleared by User=SYSTEM, Cannot dermine p

Reply
Thread Tools Display Modes

Security Event Logs being cleared by User=SYSTEM, Cannot dermine p

 
 
Aaron
Guest
Posts: n/a

 
      11-07-2009
OK, I am dumbfounded on this one.
Our Security event logs are being cleared. This is a serious violation of
out ITRM policy for obvious reasons. The event log states USER=system.
Clearing always occurs at the top of the hour. This behavior is indicative
of a script or EXE. All the obvious have been checked; GPO and scheduled
tasks. We have checked the other logs, and nothing occurs around the same
time. The SA team is thinking it is an application proc doing this, but I
need definitive proof of the root cause.
Is there any other logs, or auditing that will show what proc, running under
the system context, is clearing the security log? Or does anyone know of a
free app that has more granular auditing.
I am hoping this community can help me before I open a case with MS

Thanks In Advance
Aaron
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Repair DNS 4010 events... Jake Windows Server 1 11-04-2009 10:20 AM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 06:02 PM
Security Event ID: 529 Nick Windows Small Business Server 1 10-27-2009 11:04 PM
event logs on win2008 server inenewbl Windows Server 1 10-25-2009 11:42 AM
Event logs thousands of errors. john stuart Windows Vista Performance 0 12-26-2007 08:29 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59