Auditing Terminal service: strange trouble

  • Thread starter Thread starter RedFoxy
  • Start date Start date
R

RedFoxy

Hi all!
I've actived the auditing of terminal services but i've a strange trouble...

I found a lot of connections but i've an hole in the sequences of
connections, i've connections from rdp-tcp#3 to rdp-tcp#17 and after
rdp-tcp#19 but i've a snapshot where i see rdp-tcp#18 but it isn't
logged in the event log, is it possible?

I've enabled the audit just running "actve directory user and computer"
then i right click on the domain tree and i selected propriety, after
that i clicked on group plocy and then on open button, in that window i
do "create and link a GPO here" and i call it Audit, then i edited it
and i goes to Computer config -> Windows settings-> local protection ->
local policy -> audit policy -> and i've enabled "audit account logon
events", "Audit logon events", "audit account management", "Audit system
events"

But after i activated it i don't see new terminal server connections in
the event log....
 
Back
Top