Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > SNMP Security Event Logs

Reply
Thread Tools Display Modes

SNMP Security Event Logs

 
 
Steve Gould
Guest
Posts: n/a

 
      04-24-2009
Recently I was going through the Security logs on a number of servers
looking at successful logons. I noticed an oddity. Every 5 minutes an event
540 and 538 were being recorded from an employee account who had moved to a
different department. This worried me at first until I tracked down the
cause. We have a server monitor that uses SNMP and hits the servers every 5
minutes.

Here is the weird part. When SNMP is touched, or the service restarted, a
Security event ID 540 and 538 are logged using the user name of the account
that was logged on when SNMP was first installed. I have verified this on
numerous servers.

I don't like this situation as it muddies the logs a bit. The service should
log as SYSTEM if anything.

Does anyone know if this can be altered?

Thanks,

Steve


 
Reply With Quote
 
 
 
 
Mel K.
Guest
Posts: n/a

 
      05-08-2009
SNMP Service should run under Local System Account by default (Server 2003
SP2). Check the service logon settings and change if necessary.

--
Thank you,
Mel K.
MCSA: M
"Steve Gould" <steven.gould at seattle.gov> wrote in message
news:...
> Recently I was going through the Security logs on a number of servers
> looking at successful logons. I noticed an oddity. Every 5 minutes an
> event 540 and 538 were being recorded from an employee account who had
> moved to a different department. This worried me at first until I tracked
> down the cause. We have a server monitor that uses SNMP and hits the
> servers every 5 minutes.
>
> Here is the weird part. When SNMP is touched, or the service restarted, a
> Security event ID 540 and 538 are logged using the user name of the
> account that was logged on when SNMP was first installed. I have verified
> this on numerous servers.
>
> I don't like this situation as it muddies the logs a bit. The service
> should log as SYSTEM if anything.
>
> Does anyone know if this can be altered?
>
> Thanks,
>
> Steve
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SNMP Security Event Logs Steve Gould Windows Server 1 05-08-2009 02:49 PM
Can't access Event Logs other than Security Newbie Active Directory 2 05-18-2006 02:30 AM
security event logs in DC as well ? SOS Simo Sentissi Server Security 2 05-04-2006 07:40 PM
MMC - Event Viewer - Command Line - Cannot access security event logs Alan Windows Small Business Server 3 04-21-2006 10:41 AM
Security Event Logs Carl Hilton Server Security 1 06-11-2005 09:15 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59