Difference between revisions of "Windows"

From Mesopoly 3.0
Jump to navigation Jump to search
Line 10: Line 10:
 
Audit Logon/Logoff success events. The logon (528/540) and logoff (538
 
Audit Logon/Logoff success events. The logon (528/540) and logoff (538
  
*[http://www.microsoft.com/technet/security/bestprac/bpent/sec3/monito.mspx events by ID at microsoft]
+
 
 
*[http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en Windows Server 2003 resource kit tools]
 
*[http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en Windows Server 2003 resource kit tools]
  
 
[[Category:Technical]]
 
[[Category:Technical]]

Revision as of 13:01, 24 March 2006

  • You have windows network and you would like monitor user login / logoff.
  • You have already searched the web and usenet trying to find suitable recipies but found none to concise
    • Windows 2003 server came with heaps of new auditing features and many of those are published but silent fact remains, that simple logon / logoff monitoring is not part of default reports.
    • your network may not be win2003 network at all. you may entertain win2000 or even serverless network.
  • FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 for logon and 538 for logoff. More on Microsoft Event ID
    • Take care you dont confuse these with 'account logon' events which are something else and have different IDs
    • you can start logging of these either locally or via group policy

Audit Logon/Logoff success events. The logon (528/540) and logoff (538