Windows 2003 Security Policy / Auditing / Event Logs - Please Help!

  • Thread starter Thread starter Rafael
  • Start date Start date
R

Rafael

I'd be really grateful for some help please. I'm a newbie!!

I have a Dell Latitude laptop running Windows XP Pro.

The Security event log on this machine has hundreds of 'Success Audit'
type entries. They are mainly events 528, 538, and 576 (Logon/Logoff,
Privilege Use etc). When I say hundreds, I mean there appears to be an
average of about 4 per minute under normal use.

Whenever I have looked at the Security event log on other machines, 9
times out of 10 there's only one 'Success Audit' type entry there.

I have looked at Control Panel --> Administrative Tools --> Local
Security Policy --> Local Policies --> Audit Policies on the laptop.
Everything is configured as 'No Auditing' with the exception of 'Audit
account logon events' and 'Audit logon events'. These are set as
'Success, Failure' however, when I click on 'Properties' for each of
these, the options to audit successes and / or failures are selected
but greyed out and I cannot change them.

To be honest, this is just about where I come unstuck although I have
*tried* to do some research and I think this must be because there is
a Domain Security Policy. I have Administrator access to the Domain
Controller / Windows 2000 Server (SP4) but I don't know what to do
now.

The odd thing is that there are other machines in the Domain which
don't have this intensive Security event logging.

Any advice greatly appreciated. I am more than happy to provide
whatever further information you need in order to help me resolve
this.

Thank you in advance.
 
Back
Top