Auditing Logon Events

  • Thread starter Thread starter Richard Ling
  • Start date Start date
R

Richard Ling

I am running windows 2000 DC (SDS 2000, DNS, DHCP, Exchange AD)

I am trying to audit when users log on and off the domain. I have setup the
relivant entries in the Security Policy for the domain controler. In the
security log I am getting many events logged for SYSTEM and other things
like exchange. Is there a way to filter this out so I just Audit users in a
specific group or groups?

Thanks



Richard
 
Run > MMC > Add Remove Snap-Ins > Event Log > and use filter tab to specify
Event IDs or user accounts/ groups.

The benefit is that you can then save the mmc with a specific filter
configured. Additional consoles can be saved as well with different filter/
view configurations.

There are a number of 3rd party tools that can provide various options,
search at www.google.com.
 
Back
Top