Security Event Log


a little frustrated here, windows security log on our server out of control. generating 250,000+ events in less day @ point prunes log. 80% of them logon/logoff events. have total of 35 users should generate less 100 actual tangible logons/logoffs (i know there other logon types).

i understand there needs more records want in order provide useful information. current settings polar opposite making difficult parse kind of usable information out of mountain of data. if didn't care limited time, ridiculous logging 150mb of kerberos tickets , other minutia daily. if wanted store 6 months of logs require 27 gb of space.

there must happy medium normal small businesses want useful information don't need forensic level logging. example, application log. noisy, can scroll through few days of events , pick out obvious problems need attention.

thanks listening me whine :) , help/suggestions.

hi,

you may consider configure advanced security audit policy settings,there sub categories of account logon such audit kerberos authentication service , audit kerberos service ticket operations may disable.

please note if want modify settings within advanced security audit policy , make sure enable policy force audit policy subcategory settings (windows vista or later) override audit policy category settings, under computer configuration\windows settings\security settings\local policies\security options, otherwise, modified settings within advanced security audit policy won't apply.

more information you:

advanced security audit policy settings

https://technet.microsoft.com/en-us/library/dd772712%28v=ws.10%29.aspx?f=255&mspperror=-2147217396

account logon

https://technet.microsoft.com/en-us/library/dd772662%28v=ws.10%29.aspx?f=255&mspperror=-2147217396

audit: force audit policy subcategory settings (windows vista or later) override audit policy category settings

https://technet.microsoft.com/en-us/library/jj852246(v=ws.10).aspx

best regards,
amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group