KWestos Posted November 4, 2008 Posted November 4, 2008 My security log is going into overdrive - please see attached screen shot. Anyone got any ideas. I think this is causing my machine to periodically lose network connections also
sharkster Posted November 4, 2008 Posted November 4, 2008 only joking don't have a clue what its doing :S
Diello Posted November 4, 2008 Posted November 4, 2008 Seems you have Auditing set to report on everything! have you checked your Local Security Policy?
KWestos Posted November 4, 2008 Author Posted November 4, 2008 (edited) I have just found out that it happens on all other machines too! Edited November 4, 2008 by KWestos
KWestos Posted November 4, 2008 Author Posted November 4, 2008 Seems you have Auditing set to report on everything! have you checked your Local Security Policy? Is this local security policy within active directory?
SYNACK Posted November 4, 2008 Posted November 4, 2008 If it is happening on all machines that would indicate that it is probably a domain based policy, it will be under the computer config > windows settings > security settings > local policies > audit policies of one of your policies. It may be quickest to run the RSoP snapin on the server or use the gp managment console to make a summary of all the policies that are appling and then see which of your domain policies is set to enable auditing
KWestos Posted November 4, 2008 Author Posted November 4, 2008 If it is happening on all machines that would indicate that it is probably a domain based policy, it will be under the computer config > windows settings > security settings > local policies > audit policies of one of your policies. It may be quickest to run the RSoP snapin on the server or use the gp managment console to make a summary of all the policies that are appling and then see which of your domain policies is set to enable auditing Out of the 9 possible policy settings - which ones do you or others have set?
KWestos Posted November 4, 2008 Author Posted November 4, 2008 I have now switched off all policy settings for auditing and I still get all the messages every 3 or 4 minutes - help!
KWestos Posted November 4, 2008 Author Posted November 4, 2008 Having stopped all the auditing from active directory, I think I may have solved it. When I stopped them on AD the local policies kicked in and I forgot about these. I have stopped these logging for the time being and it seems to have sorted it. I will probably enable them one by one to get a good balance of logging audits. What do other people use, i.e. which policies are set. Jesus - I just realised the time. 22:45 - I've been logged in from home for 4 hours! what a sad git!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now