Click here to get back home

Event Log Access

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Event Log Access Steve Harclerode 07-08-2005
  ---> Re: Event Log Access Steve Harclerod...07-08-2005
  |   `--> Re: Event Log Access Steve Harclerod...07-08-2005
  `--> Re: Event Log Access Steve Harclerod...07-08-2005
Posted by Steve Harclerode on July 8, 2005, 1:35 pm
Please log in for more thread options
Hi,

I'm trying to look at the Application event log on a Windows 2003 server
using the Event Viewer. The account I'm using is a member of the local admin
group. I'm getting an error:

Unable to complete the operation on "Application". Access is Denied".

Is this a common problem? What could our administrator change to allow me
access to those logs?

Thanks,
Steve




Posted by Steven L Umbach on July 8, 2005, 3:45 pm
Please log in for more thread options
No that is not a common problem. Is this happening to everyone including the
built in administrator account? Are you logging on locally or trying to do
this remotely? The guests group can be denied access to the application log
but it would be unusual for you to be a member of the gusts group but you
should have your user account membership reviewed. The command net user
username is an easy way to do such. Can you access any log - system or
security for example? --- Steve


> Hi,
>
> I'm trying to look at the Application event log on a Windows 2003 server
> using the Event Viewer. The account I'm using is a member of the local
> admin group. I'm getting an error:
>
> Unable to complete the operation on "Application". Access is Denied".
>
> Is this a common problem? What could our administrator change to allow me
> access to those logs?
>
> Thanks,
> Steve
>




Posted by Steve Harclerode on July 8, 2005, 1:52 pm
Please log in for more thread options
I can access the Security log, but not the System or the Application log.
I'm a member of administrators, power users, remote desktop users, and
users.

And yes, I'm logging on remotely with Terminal Services from Win2K box.

I'll have to ask the admin guy Monday if he can access the Event Log.

Thanks,
Steve

> No that is not a common problem. Is this happening to everyone including
> the built in administrator account? Are you logging on locally or trying
> to do this remotely? The guests group can be denied access to the
> application log but it would be unusual for you to be a member of the
> gusts group but you should have your user account membership reviewed. The
> command net user username is an easy way to do such. Can you access any
> log - system or security for example? --- Steve
>
>
>> Hi,
>>
>> I'm trying to look at the Application event log on a Windows 2003 server
>> using the Event Viewer. The account I'm using is a member of the local
>> admin group. I'm getting an error:
>>
>> Unable to complete the operation on "Application". Access is Denied".
>>
>> Is this a common problem? What could our administrator change to allow me
>> access to those logs?
>>
>> Thanks,
>> Steve
>>
>
>




Posted by Steven L Umbach on July 8, 2005, 4:13 pm
Please log in for more thread options
Boy is that bizarre in that you can access the security log but not the
application or system log. There is an outside chance that they are corrupt
and clearing the logs may help but I would back them up first just in case
there is anything important in those logs and you would be prompted to do
such before you cleared them. The problem would not be network related if
you can access the security log. The other things I would check is
permissions to the .evt logs to make sure you do not have any deny
permissions to them and that administrators/system have full control and the
permissions on the registry keys for those logs which are located at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\application
and ...system . --- Steve



>I can access the Security log, but not the System or the Application log.
>I'm a member of administrators, power users, remote desktop users, and
>users.
>
> And yes, I'm logging on remotely with Terminal Services from Win2K box.
>
> I'll have to ask the admin guy Monday if he can access the Event Log.
>
> Thanks,
> Steve
>
>> No that is not a common problem. Is this happening to everyone including
>> the built in administrator account? Are you logging on locally or trying
>> to do this remotely? The guests group can be denied access to the
>> application log but it would be unusual for you to be a member of the
>> gusts group but you should have your user account membership reviewed.
>> The command net user username is an easy way to do such. Can you access
>> any log - system or security for example? --- Steve
>>
>>
>>> Hi,
>>>
>>> I'm trying to look at the Application event log on a Windows 2003 server
>>> using the Event Viewer. The account I'm using is a member of the local
>>> admin group. I'm getting an error:
>>>
>>> Unable to complete the operation on "Application". Access is Denied".
>>>
>>> Is this a common problem? What could our administrator change to allow
>>> me access to those logs?
>>>
>>> Thanks,
>>> Steve
>>>
>>
>>
>
>




Posted by Steve Harclerode on July 8, 2005, 3:17 pm
Please log in for more thread options
For completeness sake...
I looked at the registry permissions for the keys you mentioned. They all
were set so that the Admin account could read them. However, all 3 logs had
a DWORD value called RestrictGuestAccess which was set to 1. You'd think
that would have kept me from looking at the Security log, but I was
definitely able to see it.

The entire mystery isn't solved, but as I mentioned in another post, the
problem is gone. Your earlier suggestion fixed it.

Thanks,
Steve

> Boy is that bizarre in that you can access the security log but not the
> application or system log. There is an outside chance that they are
> corrupt and clearing the logs may help but I would back them up first just
> in case there is anything important in those logs and you would be
> prompted to do such before you cleared them. The problem would not be
> network related if you can access the security log. The other things I
> would check is permissions to the .evt logs to make sure you do not have
> any deny permissions to them and that administrators/system have full
> control and the permissions on the registry keys for those logs which are
> located at
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\application
> and ...system . --- Steve
>
>
>
>>I can access the Security log, but not the System or the Application log.
>>I'm a member of administrators, power users, remote desktop users, and
>>users.
>>
>> And yes, I'm logging on remotely with Terminal Services from Win2K box.
>>
>> I'll have to ask the admin guy Monday if he can access the Event Log.
>>
>> Thanks,
>> Steve
>>
>>> No that is not a common problem. Is this happening to everyone including
>>> the built in administrator account? Are you logging on locally or
>>> trying to do this remotely? The guests group can be denied access to the
>>> application log but it would be unusual for you to be a member of the
>>> gusts group but you should have your user account membership reviewed.
>>> The command net user username is an easy way to do such. Can you access
>>> any log - system or security for example? --- Steve
>>>
>>>
>>>> Hi,
>>>>
>>>> I'm trying to look at the Application event log on a Windows 2003
>>>> server using the Event Viewer. The account I'm using is a member of the
>>>> local admin group. I'm getting an error:
>>>>
>>>> Unable to complete the operation on "Application". Access is Denied".
>>>>
>>>> Is this a common problem? What could our administrator change to allow
>>>> me access to those logs?
>>>>
>>>> Thanks,
>>>> Steve
>>>>
>>>
>>>
>>
>>
>
>




Similar ThreadsPosted
Re: Access Deined event logs October 26, 2005, 9:12 pm
Access Deined event logs October 25, 2005, 8:51 am
Access denied to event viewer? December 22, 2005, 4:07 pm
Event Viewer Access Denied January 27, 2006, 12:37 pm
event viewer access denied January 5, 2007, 1:33 am
after win2000 upgrade to win2003,event log can not access March 9, 2006, 3:57 am
Remote event viewer access without being an admin? April 28, 2008, 5:04 pm
NON STOP Event log -event id 538,540,576 September 2, 2007, 11:44 pm
Re: NON STOP Event log -event id 538,540,576 October 2, 2007, 2:44 pm
Event 560 November 4, 2005, 12:51 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap