Click here to get back home

security event logs in DC as well ? SOS

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
security event logs in DC as well ? SOS Simo Sentissi 05-03-2006
Posted by Simo Sentissi on May 3, 2006, 6:06 pm
Please log in for more thread options
hello there

I am shipping all the security and application event log from servers to a
log agregation tool and i see some duplication of events from both the
domain controlers and the normal machines.
I am wondering if I even should ship the security evetn logs to the tool if
i am already shipping the security evetns from the DCs?

I have tons of duplications anybody knows ?
any ideas ? am I missing somethings ?



Posted by S. Pidgorny on May 4, 2006, 6:00 am
Please log in for more thread options
Examples of duplications, please?

I think that you are seriously impacting the potential value of log
aggregation by disabling getting logs from certain servers. It is the events
that are not duplicated that you're going to miss.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> hello there
>
> I am shipping all the security and application event log from servers to a
> log agregation tool and i see some duplication of events from both the
> domain controlers and the normal machines.
> I am wondering if I even should ship the security evetn logs to the tool
> if i am already shipping the security evetns from the DCs?
>
> I have tons of duplications anybody knows ?
> any ideas ? am I missing somethings ?
>



Posted by Steven L Umbach on May 4, 2006, 3:40 pm
Please log in for more thread options
I don't know how you are seeing duplicate events because what is recorded in
the security log is what is happening on that computer. For instance when
auditing of logon events is enabled on a computer it will show when a
computer/user attempts to access the computer either via interactive logon
or via network share such as type 3 logon. These events would not be
recorded on a domain controller. You might however see an "account logon"
event recorded on a domain controller at the sane time as you see a logon
event on a domain computer because the user is authenticating to the domain
controller. You would not however see hack attempts on the domain computer
for " local" user accounts such as the built in administrator account in the
security log of a domain controller as account logon attempts. They would
only show in the security log of the domain computer. -- Steve


> hello there
>
> I am shipping all the security and application event log from servers to a
> log agregation tool and i see some duplication of events from both the
> domain controlers and the normal machines.
> I am wondering if I even should ship the security evetn logs to the tool
> if i am already shipping the security evetns from the DCs?
>
> I have tons of duplications anybody knows ?
> any ideas ? am I missing somethings ?
>



Similar ThreadsPosted
Security Event Logs June 10, 2005, 8:36 am
Event ID 577 Filing Security Logs July 19, 2006, 10:45 am
Reading Security Event Logs with Service Account November 15, 2007, 7:36 pm
Rights to event logs June 15, 2005, 2:03 pm
Re: Access Deined event logs October 26, 2005, 9:12 pm
Access Deined event logs October 25, 2005, 8:51 am
RE: Who/What is sft@loader.com in our IIS Logs? MSFTPSVC Event 10 November 19, 2007, 7:38 am
RE: Who/What is sft@loader.com in our IIS Logs? MSFTPSVC Event 10 February 21, 2008, 4:20 pm
Windows Server 2003 event logs May 2, 2006, 3:29 pm
Event ID 2003 Unable to open the performance logs and alerts confi May 30, 2006, 6:28 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap