After enabling audit security events are not logged


we have enabled audit policies 2 windows 2008 servers. (audit  success/failiure logon,logoff,fileshare, file system, handle manipulation, registry) 

after applying policies checked in both server; can able see audit events in 1 server

but in server no single events logging; tried clear security logs  no more logs logging.

normal logon , logoff events not logging in that server??. can me fix this???

hi,

please make sure overwrite events needed(oldest events first) check box had been selected.

for details:

1. event viewer -> windows logs -> security
2. right click security, point properties, select overwrite events needed(oldest events first) check box

please confirm system , adminstrators account has full control permission, eventlog account has read permission hkey_local_machine\system\currentcontrolset\services\eventlog\security, restart computer.


if issue persist, please try use group policy result see policy applied or not.

1. run gpresult /h gpresult.html
2. run gpresult.html

if policy apply successfully, please try recreate new security log

for details:

a. start -> run, input services.msc, double click windows event log. change setup type disabled.
b. reboot computer.
c. go c:/windows/system32/winevt/logs, , change security.evtx security_old.evtx.
d. start -> run, input services.msc, double click windows event log. change setup type automatic.
e. reboot computer. , new security.evtx generated.

hope helps!

best regards
elytis cheng


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client