Professional Documents
Culture Documents
EVENT LOGS
Windows Event Logging
Service started during boot to log warnings, exceptional
conditions and other administrative messages
*If Overwrite rule is not met when log file reaches max size, then new events will NOT get
recorded.
Default Storage Location %systemroot%\system32\config
For best practice or Microsoft recommended maximum event log size please
see:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-
server-2008-R2-and-2008/dd349798(v=ws.10)
Registry Information
HKLM\SYSTEM\CurrentControlSet\Services\EventLog
Event Sources
It can’t be stopped
At least NOT with
‘Task Manager’
Default Event Logs…
• Application Log…
• Event types…
• System Log…
• Event types…
• Preset OS events…
• Security Log…
• Event types
• Preset security events where
the success or failure is
reported
Security - Event Logging
• Local Security Authority Subsystem Service (LSASS) runs at startup and log
events are recorded based on the ‘Audit Policy’
• Security Reference Monitor (SRM), which monitors objects, also reports to
the LSASS
• Windows 2K/XP NO LSASS logging by default
• Later OS versions (from Windows Server 2003, logging active
• LSASS has a preset number of events that can be logged
• SRM, security of objects (files, folders printers etc.) not part of this
presentation
Security Event Log – Audit Policy
• Preset number of events
• Success and/or Failure event generates log entry
• Settings>Control Panel>Administrative Tools>Local Security Policy or Run the
program ‘gpedit.msc’
• Must have Administrators Account
Security Event Log Auditing
• Events are
identified by their
‘Event ID’
• Properties….
• Filtering…
Some Event ID’s…
• Event ID 529 Logon
Failure
• Event ID 528 Logon
Success
• Event ID 551 User
Initiated Shutdown
• What about the URL…
• More event ID’s
Archived Event Logs
Created by User
For example:
Storage Location
Log file structure and file extension
The number of log files
Event Logs
Event Logs
Event Logs
Event Logs
Event Logs
The Event Log Viewer provides enhanced functionality in comparison to that supplied with XP