G
Guest
I’ve been asked to modify what DC’s audit to make it easier to identify user
logon and logoff events. I only need data/times for logging on/off
workstations for documenting when employees start and end their work day. I
do not need to log every authentication event every time the employee
accesses a network resource. Based on the articles I’ve read, “Audit Logon
Events†in the Default DC Policy seems to be the events I’m looking for;
however even with all other audit policies being undefined I still get
multiple events every minute (one event every 1 – 5 seconds) in the security
log. I built a test domain (Windows 2000 – native) consisting of one DC and
one workstation. The default domain policy’s audit entries are all set to
“Not defined†and the default domain controllers policy’s “Audit logon
events†is set to record “success†events. There are no other GPO’s. How
can I further reduce logged events to be more concise?
logon and logoff events. I only need data/times for logging on/off
workstations for documenting when employees start and end their work day. I
do not need to log every authentication event every time the employee
accesses a network resource. Based on the articles I’ve read, “Audit Logon
Events†in the Default DC Policy seems to be the events I’m looking for;
however even with all other audit policies being undefined I still get
multiple events every minute (one event every 1 – 5 seconds) in the security
log. I built a test domain (Windows 2000 – native) consisting of one DC and
one workstation. The default domain policy’s audit entries are all set to
“Not defined†and the default domain controllers policy’s “Audit logon
events†is set to record “success†events. There are no other GPO’s. How
can I further reduce logged events to be more concise?