Enable Audit Policy object access: too many logs generated on event viewer


hello everybody,

i've issue object access definition on audit policy in customer; below details:

active directory forest: 2008 r2

members servers: 2008, 2008 r2 , 2003.

i've applied account logon on default domain controller audit domain access ad works fine.

when enable access object (success, failure) other member servers, located in specific ou, many events in local security logs generated.

my purpose log object access administrators group on member servers, can see many 560 , 562 logs, , log everybody.

how can solve issue?

thank much

best regards

object acess 2 part scenario: first, have enable object
acess audit logging (you did that). second, have enable
auditing on individual objects (sacl). check events
receiving , edit security settings ("advanced", "auditing") of
the objects in question needs.
 

no not evil, if know doing: or bad gpos?
wenn meine antwort hilfreich war, freue ich mich über eine bewertung! if answer helpful, i'm glad rating!


Windows Server  >  Group Policy



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...