Oaktech Posted December 17, 2013 Posted December 17, 2013 Our CC3 domain controllers have a policy whereby they only log security failure audit events, and not successes... this is becoming an issue as our Palo Alto reads these logs looking for events 672, 673 and 675 to determine who is logged into a machine. If I change the group policy to log success audit is the RM world going implode? We've ended our support contract with RM now as we are going to be migrating in the summer away from RM, so I can't ask them! 'Elp.
AngryTechnician Posted December 17, 2013 Posted December 17, 2013 It should not cause any major issues with CC3. Your main concern will be log size, and therefore retention period. You will typically have at least 1 order of magnitude more success audits than failure audits, so you will reach the maximum log size much more quickly once they enabled, leading to a much shorter log retention period (unless you increase the maximum log size).
Oaktech Posted December 17, 2013 Author Posted December 17, 2013 Thanks for that. I've taken the plunge and we'll see what happens tomorrow...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now