Failure audits in Event logs
hi,
my security logs on 2008 r2 dcs full of following failure audits:
log name: security
source: microsoft-windows-security-auditing
date: 7/1/2011 8:51:00 am
event id: 4662
task category: directory service access
level: information
keywords: audit failure
user: n/a
computer: dc1.microsoft.msft
description:
operation performed on object.
subject :
security id: domain\usercomputer$
account name: usercomputer$
account domain: domain
logon id: 0x3d71bc79
object:
object server: ds
object type: computer
object name: cn=usercomputer,ou=xxx,ou=xxx,ou=xxx,dc=microsoft,dc=msft
handle id: 0x0
operation:
operation type: object access
accesses: control access
access mask: 0x100
properties: ---
{771727b1-31b8-4cdf-ae62-4fe39fadf89e}
{aa4e1a6d-550d-4e05-8c35-4afcb917a9fe}
{bf967a86-0de6-11d0-a285-00aa003049e2}
additional information:
parameter 1: -
parameter 2:
i want rid logs huge amount of such events. seems of our machines cause such events. how troubleshoot such events? thanks.
this auditing new 2008. have amount of control on gets logged. have @ technet article details , options:
http://technet.microsoft.com/en-us/library/cc731764(ws.10).aspx
otherwise, may want consider creating custom view in event log. way, can maintain information possible in logs see want based on given situation. can create custom view displays critical or error events.
brian
Windows Server > Security
Comments
Post a Comment