Failure audits in Event logs


hi,

my security logs on 2008 r2 dcs full of following failure audits:

log name:      security
source:        microsoft-windows-security-auditing
date:          7/1/2011 8:51:00 am
event id:      4662
task category: directory service access
level:         information
keywords:      audit failure
user:          n/a
computer:      dc1.microsoft.msft
description:
operation performed on object.

subject :
    security id:        domain\usercomputer$
    account name:        usercomputer$
    account domain:       domain
    logon id:        0x3d71bc79

object:
    object server:        ds
    object type:        computer
    object name:        cn=usercomputer,ou=xxx,ou=xxx,ou=xxx,dc=microsoft,dc=msft
    handle id:        0x0

operation:
    operation type:        object access
    accesses:        control access
               
    access mask:        0x100
    properties:        ---
        {771727b1-31b8-4cdf-ae62-4fe39fadf89e}
            {aa4e1a6d-550d-4e05-8c35-4afcb917a9fe}
    {bf967a86-0de6-11d0-a285-00aa003049e2}


additional information:
    parameter 1:        -
    parameter 2:       

i want rid logs huge amount of such events. seems of our machines cause such events. how troubleshoot such events? thanks.

this auditing new 2008.  have amount of control on gets logged.  have @ technet article details , options:

http://technet.microsoft.com/en-us/library/cc731764(ws.10).aspx

 

otherwise, may want consider creating custom view in event log.  way, can maintain information possible in logs see want based on given situation.  can create custom view displays critical or error events.

 

brian



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group