Event Log Readers


we want provide second line capability troubleshoot lockout events in ad. added second line support group (global group), builtin\event log readers in should access security log on domain controllers.

we noticed second line did not have access although should. inspected default domain controller policy , saw tempered previous administrator. therefore decided reset default domain controller policy defaults (dcgpofix -target:dc).

after resetting domain controller policy, second line support able access event log on domain controllers when open local event viewer on local computers. eventcombmt still fails. 

in troubleshooting saw error when applying security client side extension of domain controller policy. after enabling advance logging, see following problem:

 

----configure user rights...
configure s-1-5-32-544.
configure s-1-5-20.
configure s-1-5-19.
configure s-1-5-32-551.
configure s-1-5-32-549.
configure s-1-5-32-559.
configure s-1-5-21-3044489760-2976449867-2277937539-500.
configure s-1-5-21-3044489760-2976449867-2277937539-1957.
configure s-1-5-32-554.
configure s-1-5-11.
configure s-1-1-0.
configure s-1-5-9.
configure s-1-5-32-550.
configure s-1-5-32-548.
configure s-1-5-21-3044489760-2976449867-2277937539-5212.
configure s-1-5-21-3044489760-2976449867-2277937539-0.
configure s-1-5-32-573.
configure s-1-5-21-3044489760-2976449867-2277937539-1194.
configure s-1-5-21-1516777378-324351553-1241804275-8908.

user rights configuration completed successfully.


----configure group membership...
warning 2: system cannot find file specified.
cannot find event log readers.
configure event log readers.
aliases cannot members of other groups.

group membership configuration completed 1 or more errors.


 have checked group builtin\event log readers, , ssid correct. 

configure s-1-5-32-573.

our second line team members assigned global group within domain , resource (event log readers) has been assigned global group (memberof -> agdlp).

even after removing global group member of event log readers, same error displayed.

can give me clue's in how resolve issue? 


answers provided coming personal experience, , come no warranty of success. else make mistakes.

hi,

the below article has step-by-step guide setting event log permissions.you check reference:

giving non administrators permission read event logs windows 2003 , windows 2008

http://blogs.technet.com/b/janelewis/archive/2010/04/30/giving-non-administrators-permission-to-read-event-logs-windows-2003-and-windows-2008.aspx


best regards
cartman
please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group