Missing Audit events in Windows Security Log


hi all!

i've discovered i'm missing events in secirity log on med dc's.

it's 2008r2 domain/forest on 2008r2 domain controllers.

i've been tracking ad-account lock-outs before (some months back) , need again, can't find events on dc's relating users getting locked out.

example: no audit failure events id 4768 or 4771 in of logs on dc's, if users try log on computers wrong credentials, , locked out.

first thing checked default dc policy , it's got auditing enabled - i'm not using adv. audit pol. conf. - regular audit policy settings:
  audit account logon events: success, failure
  audit account management: success, failure
  audit logon events: success, failure
  - rest set failure only.

gp results wizard shows expected, , there no warnings in system log related applying gpos.

so start looking next??

cheers


ullethebulle

hi,

we run below command admin right audit settings on computer:

auditpol /get /category:*

please check if account lockout auditted.

if settings right configured, suggest check local event viewer user locked out, , try find event. , may check other dcs find related event.

regards,

yan li


cataleya li
technet community support



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group