Missing Audit events in Windows Security Log
hi all!
i've discovered i'm missing events in secirity log on med dc's.
it's 2008r2 domain/forest on 2008r2 domain controllers.
i've been tracking ad-account lock-outs before (some months back) , need again, can't find events on dc's relating users getting locked out.
example: no audit failure events id 4768 or 4771 in of logs on dc's, if users try log on computers wrong credentials, , locked out.
first thing checked default dc policy , it's got auditing enabled - i'm not using adv. audit pol. conf. - regular audit policy settings:
audit account logon events: success, failure
audit account management: success, failure
audit logon events: success, failure
- rest set failure only.
gp results wizard shows expected, , there no warnings in system log related applying gpos.
so start looking next??
cheers
ullethebulle
hi,
we run below command admin right audit settings on computer:
auditpol /get /category:*
please check if account lockout auditted.
if settings right configured, suggest check local event viewer user locked out, , try find event. , may check other dcs find related event.
regards,
yan li
cataleya li
technet community support
Windows Server > Security
Comments
Post a Comment