Jump to content

Recommended Posts

Posted

Our CC3 domain controllers have a policy whereby they only log security failure audit events, and not successes... this is becoming an issue as our Palo Alto reads these logs looking for events 672, 673 and 675 to determine who is logged into a machine.

 

If I change the group policy to log success audit is the RM world going implode?

 

We've ended our support contract with RM now as we are going to be migrating in the summer away from RM, so I can't ask them!

 

'Elp.

Posted
It should not cause any major issues with CC3. Your main concern will be log size, and therefore retention period. You will typically have at least 1 order of magnitude more success audits than failure audits, so you will reach the maximum log size much more quickly once they enabled, leading to a much shorter log retention period (unless you increase the maximum log size).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...