Click here to get back home

Security Log file full often

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security Log file full often Troy 12-22-2005
Posted by Troy on December 22, 2005, 12:01 pm
Please log in for more thread options
I have a workstation that the security log file gets full every few days. I
saved and cleared the log file again this morning. The only entries are
events 538 and 540's from the domain controller and another workstaion.
Why am I seeing anonymous logins from another workstation?

thanks!



Posted by Jon Phipps on December 22, 2005, 12:09 pm
Please log in for more thread options
not only do the users have to log on to the domain but the computers do as
well when they start up. Most of the time the workstns logon anonymously,
dont forget that there is an enormous amount of traffic even when nobody is
logged on, mainly network maint packets... computers finding eachother etc.
"Troy" <nospam> wrote in message
>I have a workstation that the security log file gets full every few days.
>I
> saved and cleared the log file again this morning. The only entries are
> events 538 and 540's from the domain controller and another workstaion.
> Why am I seeing anonymous logins from another workstation?
>
> thanks!
>
>



Posted by Steven L Umbach on December 23, 2005, 1:08 pm
Please log in for more thread options
By default the security log is very small in size and you may want to
increase it to at least 5MB. Anonymous logons are normal in a network where
you are using file and print sharing and netbios over tcp/ip is enabled as
the computer browser service uses anonymous logon/null sessions to build and
maintain the browse list that you see in My Network Places. Of course you
should only be seeing computer names you recognize using a firewall to
protect your network from untrusted networks such as the internet. This
particular computer could also be seeing more then normal activity if it is
a master browser or backup browser. You can use the command nbtstat -n to
see if it is either of those. --- Steve

Example of nbtstat -n output


D:\Documents and Settings\Steve>nbtstat -n

Local Area Connection:
Node IpAddress: [192.168.1.52] Scope Id: []

NetBIOS Local Name Table

Name Type Status
---------------------------------------------
STEVE-XP <00> UNIQUE Registered
WORKGROUP <00> GROUP Registered
STEVE-XP <20> UNIQUE Registered
WORKGROUP <1E> GROUP Registered
WORKGROUP <1D> UNIQUE Registered
..__MSBROWSE__.<01> GROUP Registered


"Troy" <nospam> wrote in message
>I have a workstation that the security log file gets full every few days.
>I
> saved and cleared the log file again this morning. The only entries are
> events 538 and 540's from the domain controller and another workstaion.
> Why am I seeing anonymous logins from another workstation?
>
> thanks!
>
>



Similar ThreadsPosted
disk full June 11, 2007, 5:22 am
Allow ONLY "Administrator" and "System" groups full control to C:\ February 15, 2006, 4:51 pm
Create a domain account with full access to all files and folders? October 24, 2006, 11:03 am
Trusted NT domain users have full access to 2K3 server shares January 23, 2007, 6:51 am
File Security July 10, 2007, 6:51 pm
File Security August 4, 2008, 9:04 pm
security template in .ini file? December 3, 2005, 10:08 pm
File xfer Security December 10, 2007, 2:32 pm
File Security Permissions January 16, 2008, 11:03 am
Auditing File Share Security February 5, 2007, 3:44 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap