Difference between revisions of "Windows"

From Mesopoly 3.0
Jump to navigation Jump to search
Line 4: Line 4:
 
** your network may not be win2003 network at all. you may entertain win2000 or even serverless network.
 
** your network may not be win2003 network at all. you may entertain win2000 or even serverless network.
  
*FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 for logon and 538 for logoff. More on Microsoft [http://www.microsoft.com/technet/security/bestprac/bpent/sec3/monito.mspx Event ID]
+
*FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 for logon and 538 for logoff. More on microsoft [http://www.microsoft.com/technet/security/bestprac/bpent/sec3/monito.mspx Event ID]
 
**Take care you dont confuse these with 'account logon' events which are something else and have different IDs
 
**Take care you dont confuse these with 'account logon' events which are something else and have different IDs
 
** you can start logging of these either locally or via group policy.Audit Logon/Logoff success events.
 
** you can start logging of these either locally or via group policy.Audit Logon/Logoff success events.
Line 11: Line 11:
  
  
*[http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en Windows Server 2003 resource kit tools]
+
*Download [http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en Windows Server 2003 resource kit tools]. Dont worry you can run them on WinXP. Tool you are interested in is Event Comber. There is such download for Windows 2000 also, I am yet to find it again on microsoft site.
  
 
[[Category:Technical]]
 
[[Category:Technical]]

Revision as of 13:23, 24 March 2006

  • You have windows network and you would like monitor user login / logoff.
  • You have already searched the web and usenet trying to find suitable recipies but found none to concise
    • Windows 2003 server came with heaps of new auditing features and many of those are published but silent fact remains, that simple logon / logoff monitoring is not part of default reports.
    • your network may not be win2003 network at all. you may entertain win2000 or even serverless network.
  • FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 for logon and 538 for logoff. More on microsoft Event ID
    • Take care you dont confuse these with 'account logon' events which are something else and have different IDs
    • you can start logging of these either locally or via group policy.Audit Logon/Logoff success events.



  • Download Windows Server 2003 resource kit tools. Dont worry you can run them on WinXP. Tool you are interested in is Event Comber. There is such download for Windows 2000 also, I am yet to find it again on microsoft site.