User auditing

M

Mike Richter

I have enabled log on successful and failure auditing for all of the DC's in
my environment...

I have also made the security event log file to 200MB max size...


is this a good idea... and what event ID number should I look for if I want
to know about the users log on time and date?

thanks
 
T

Tomasz Onyszko

Mike said:
I have enabled log on successful and failure auditing for all of the DC's in
my environment...

Just to be sure - You have enabled the "audit account logon" setting ?
I have also made the security event log file to 200MB max size...

I don't know the logon request volume in Your network but I'm personally
trying to avoid such big logs (sometimes the event log file can
become corrupt and You will loose a lot of data) - I preffer to set
smaller log files and import logs on regular basis to some external
database

And you don't mentioned how You set the log retention method
is this a good idea... and what event ID number should I look for if I want
to know about the users log on time and date?
Check this article:
http://www.microsoft.com/technet/prodtechnol/windows2000serv/maintain/monitor/logonoff.mspx
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top