Event Log Readers
we want provide second line capability troubleshoot lockout events in ad. added second line support group (global group), builtin\event log readers in should access security log on domain controllers. we noticed second line did not have access although should. inspected default domain controller policy , saw tempered previous administrator. therefore decided reset default domain controller policy defaults (dcgpofix -target:dc). after resetting domain controller policy, second line support able access event log on domain controllers when open local event viewer on local computers. eventcombmt still fails. in troubleshooting saw error when applying security client side extension of domain controller policy. after enabling advance logging, see following problem: ----configure user rights... configure s-1-5-32-544. configure s-1-5-20. configure s-1-5-19. configure s-1-5-32-551. configure s-1-5-32-549. configure s-1-5-32-559. configure s-1-5-21-3044489...