System and security logs

1. Login, Clear Logs and log off events in Windows 2003 when does this happen and what are the IDs for
these events ?  what is the system login?
2. In an event when administrator account and password are shared by more than one person, is it is possible
to prove who cleared the security logs?
3. If there is no keyboard monitoring is there a way to prove from which PC the delete came from?
4.  Can a schedule a task be run in advance to delete the security logs at a later point of time in Window
2003 using utilities like WMI, powershell etc?
5. In Windows 2003 servers, Microsoft allows 2 remote connections and 1 console session also called session
0. What is session 0 ans when is this launched?
6.  Can security and the system logs on the  server be deleted remotely from any other server in
windows 2003 if the account has admin rights? Please comment if firewall setting needs to be enabled in window 2003. 
dhomya

1.) If you enable auditing here are the events
https://technet.microsoft.com/en-us/library/cc787567%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
2.) Probably not unless you know who was at what console at what time.
3/4.)
http://blogs.msdn.com/b/ericfitz/archive/2007/08/10/help-someone-has-deleted-events-from-my-windows-event-log.aspx
5.) http://support.microsoft.com/kb/278845
6.) See 3/4
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows]
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

Similar Messages

  • How do you clear system and application logs in a server?

    Hello all,
    How do you clear system and application logs in a server?
    thanks,
    mike

    go to start button,all programs,assosories, System tools T event viewer. now select application & rt click & clear & do not save.similarly do for sytem too.

  • Strange Entries in System and Console Logs

    I have some strange entries in my system and console logs. In the system log, I regularly see these entries:
    Feb 24 21:07:29 joseph-youngs-computer /System/Library/PrivateFrameworks/Apple80211.framework/Resources/airport: Error: owner of process not logged in on console - exiting.
    Feb 24 21:20:32 joseph-youngs-computer kernel[0]: (82: coreservicesd)tfp: failed on 0:
    In my console log, I regularly find these entries:
    2006-02-25 09:23:24 -0600
    2006-02-24 21:07:30.530 loginwindow[803] FSResolveAliasWithMountFlags returned err = -43
    On occasion, I find something like this in my console log:
    Assert failed: /Users/dave/dev/flash/player/FlashPlayer/platform/mac/plugins/../../../core/spl ay.cpp:7105
    I admit to being something of a novice with the Mac, so I am not sure what to make of these entries, though I never noticed anything like this on my eMac, or on my prior iMac. Also, on the entry above, there are no users named dave on my Mac.
    Has anyone else noticed this, and can anyone shed any light on what these messages mean?

    Resolved with a clean install.

  • [Request] Move Windows Control Panel applet from "System and Security" to "Programs"

    The "Flash Player (32-bit)" Windows Control Panel applet should be  moved from "System and Security" to "Programs" where the Java applet is.
    Vote: https://bugbase.adobe.com/index.cfm?event=bug&id=2953107
    Thanks

    njb,
    Why not just run the ThinkVantage System Update and let it install as usual. You can also "un-check" those drivers that you don't want to install.
    *Non Lenovo employee*
    I have a Y2P (i5) ... Feel free to ping me if you want me to test some applications with your Y2P if you have the same model. I don't mind keep doing recovery on it if needed .... =)

  • System and security control panel

    Could someone with a W520 take a screenshot of the lenovo apps in their "system and security" section of control panel please. I am doing a ground up install from bare windows 7 to get rid of the preloaded SQL server 2005 and adding back the programe I want.
    Just want to seee what came preloaded.
    Thanks

    njb,
    Why not just run the ThinkVantage System Update and let it install as usual. You can also "un-check" those drivers that you don't want to install.
    *Non Lenovo employee*
    I have a Y2P (i5) ... Feel free to ping me if you want me to test some applications with your Y2P if you have the same model. I don't mind keep doing recovery on it if needed .... =)

  • System, Firewall,Secure logs

    I need some help with trying to understand the logs and whether they can be safely deleted. The only problem is I am unable to figure out what these logs do or how to delete them. Some are labeled some what oddly. I have run the maintenance scripts, but have no idea how to tell if they are working.
    I would like to clean up the logs that are using disk space. Some are rather large, but none are over 2.2mb
    Secure.log.0.bz2
    secure.log.1.bz2
    secure.log.2.bz2
    System.log
    system.log.0.bz2
    system.log.1.bz2
    system.log.2
    system.log.3.bz2
    appfirewall.log
    appfirewall.log.0.bz2
    appfirewall.log.1.bz2
    appfirewall.log.2.bz2
    appfirewall.log.3.bz2
    appfirewall.log.4.bz2
    appfirewall.log.5.bz2
    When I click on the logs in the console the trash icon is greyed out. Some of the logs light the trash icon up. Any advice or help would be appreciated.

    AFAICT, you can't delete any listed one via the Console app because the belong to the system. Leave them be, they'll get removed when appropriate by the daily maintenance script, if your machine is awake overnight. If not, run this command in the Terminal app:
    *sudo periodic daily*

  • Performance data from system and DMS logs on PDW.

    I want all of ther performance data as given below of the particular completed job with respective login ID from system or DMS logs on PDW
    What is total Memory and CPU used for completing the job?
    How many rows processed?
    What is read and write data size?
    What is disk I/O ?
    How much time taken for completing the job?
    -Prasad KVSV

    Hi Prasad, you may want to have a look at the following links:
    http://download.microsoft.com/download/5/0/1/5015A62E-06BF-4DEC-B90A-37D52E279DE5/SQL_Server_2012_Parallel_Data_Warehouse_Breakthrough_Platform_White_Paper.pdf
    http://saldeloera.wordpress.com/2012/08/27/pdw-tip-query-optimization-techniques-to-avoid-shufflemoves-and-partition-moves/
    Regards, Leo

  • LMS 3.2.1 on Solaris 10 - Setup Center / System and Security Settings Empty

    Hi All,
    When I get to the LMS Setup Center / System Settings option I can a screen that shows no options. The same happens when I try the Security Settings option.
    I've attached a capture of the screen.
    Thanks,
    Jose Ribeiro

    We're starting to see more and more users install on Oracle-branded Solaris.  There is a workaround to installing on newer Solaris.  You can modify /etc/release, and remove the word "Oracle" from the release name.  Install LMS, then restore the original file.  We're still trying to get an official word from development as to what our Solaris support plans are.

  • User Audit and Security log

    Hello Experts,
    We are using an ECC 6.0 systems. My question is apart form SM19 is there any other t_code to trace the user action that is a more detail trace on user action.
    As you know SM19 settings will offer us the basic action of user that is what t_code or reports are being used by user. But I want to know what are they doing there that is they are trying to access some infortype in t_code like PA30 or they made in table definition change in SE16 like that.
    Please let me know about this.
    Thanks in advance.
    Regards,
    Partha

    Hi Partha,
    You can use the following TCodes also.
    1. STAD
    2. STAT
    STAD and STAT can also be navigated from ST03N. If you want to log a particular TCode (for e.g. PA30), then please follow the below steps:
    Go to ST03N -> Expert user mode -> Collector & Performance DB -> Workload collector -> Parameters.
    Enter the transaction codes for the transactions to be analyzed in detail in the Create transaction detail profiles for group box. Save your changes. (please read the message carefully in this screen).
    3. STATTRACE
    4. SM21
    If you are in SM21, then please select all the options in "Settings" radio button. After getting the display of Log screen, you can further analyze a message in more details by double clicking it.
    Still SM20 is really a good choice to view user actions.
    Please re-check (in SM19) that all the Audit Classes are selected for the current filter you are analyzing. Before reading the audit log make sure to include all Instances (telling this, just to be sure).
    Mark all in "Events" and "Statistic" tabs. Now display the data selecting the particular user and tcode.
    Hope this discussion may help you to some extent. Please let me know for any more query.
    Regards,
    Dipanjan

  • DW 8.0.2 Novell Server System and FTP log-in and Password encryption

    I think I have found a bug. Dreamweaver 8.0.2, Windows XP,
    and using Novell server system. In the Novell system using Dynamic
    Local User, at each log in to Novell the user is assigned a unique
    SSID each and every time. Unfortunately Dreamweaver uses the SSID
    for the encryption key for Login and Password for the settings in
    an FTP Site. So these saved settings break at each log in to
    Novell, and give an error at the launch of Dreamweaver when it
    attempts to log into the FTP site set up.
    Dreamweaver saves the FTP Site Login and Password settings
    at: HKCU\Software\Macromedia\Common\Sites\-Site0\Keychain
    TechNote 3491671c does not fix the problem as it only fixes
    the settings location - which is fine.
    Anyone have any ideas on how to fix this?

    bikeman01 wrote:
    > As I said the problem was fixed up to php 5.2.5. Going
    to php 5.2.6. has
    > broken this again. I don't know what has changed in php
    5.2.6 that might cause
    > this.
    >
    > Are you able to confirm this problem in php 5.2.6?
    No. I have installed PHP 5.2.6 on a different machine, and
    tested the
    XSL Transformation server behavior. It works exactly the same
    as in 5.2.5.
    > If confirmed, what is the process for raising a bug and
    will Adobe fix it?
    I cannot confirm the problem, so there's nothing I can see
    for Adobe to
    fix. However, the correct channel for reporting bugs is
    through the form
    at the following address:
    http://www.adobe.com/cfusion/mmform/index.cfm?name=wishform
    Even if a problem can be identified, it's highly unlikely
    that Adobe
    would issue an updated version of the 8.0.2 hotfix. The
    hotfix worked
    perfectly with the version of PHP that was current at the
    time. Since
    then, CS3 has been released, and CS4 is being officially
    announced next
    Tuesday. If a fix is required (and I don't believe one is),
    the normal
    policy is to supply it for the current version of
    Dreamweaver, not one
    that is no longer on sale.
    David Powers, Adobe Community Expert
    Author, "The Essential Guide to Dreamweaver CS3" (friends of
    ED)
    Author, "PHP Solutions" (friends of ED)
    http://foundationphp.com/

  • Permissions fix for secure.log and iTunes frameworks

    Aperture 1.5
    PBG4 showed minor to considerable performance improvements. Once my main library finished running on the Quad, with 6600 traction engine, I started to do some real work.
    The following is in Project View on some images with patches/healing and straighten applied.
    IT WAS UGLY. SBOD every time I touched anything (yes, all previews completed). 45 secs to open the first image (8Mb RAW from Canon 20d). 5-6 secs. for any touch on Levels or Exposure. IMPOSSIBLE.
    Switched off and reduced res. of JPG's in Preferences. No difference.
    BTW Apple Devt. Spank time> There is NO way to turn off Preview creation and run as batch later that I can see. Please fix. Agreed they render in background but why not wait until you leave focus on that image .... it's recreating a preview after every adjustment I make. C'mon guys, get real, that should be fixed asap.
    Quit Aperture, restarted. Just as bad. Aperture is the only app. running, and Activity Monitor shows 319% CPU with 480Mb RAM just with a Levels change ... sounds high. 6-7 sec. response time for anything I do and 20-40 secs for image rendering, except adjacent images. Quit Aperture.
    Decided to run Repair Permissions (RAID = 0 drive). Fixed iTunes frameworks and secure.log. I believe secure.log to be the culprit.
    Restarted Aperture and performance improvements obvious. Sliders now work real-time and image rendering a couple of seconds. Reapplied Preferences setting for Previews and no significant performance degradation (though it is interesting watching the task list pause the preview generation when you make further edits.)

    It sounds like you should just turn off Maintain Previews for the project you are on (selct prj and change state in top level gear menu in prj pane) - then make your adjustments ( your previews won't be up to date then of course) but the when you are ready to make into previews just select all the images and choose Update Preview manually from the context menu.
    LC, Classic, 8500, DP2.5, MBP2.1   Mac OS X (10.4.7)   i have a cool mousepad

  • Unable to Reboot After Latest Apple Updates (SA-2011-06-23-1 and Security Update 2011-004)

    Hi All,
    After applying today's updates (06/23/2011) in APPLE-SA-2011-06-23-1 Mac OS X v10.6.8 and Security Update 2011-004, my MacBook will no longer boot. Prior to updating, the MacBook workked perfectly (except for the occasional error entry in the system and kernel log). The MackBook model number is A1278, with a RAM upgrade (4 GB).
    When booting in NORMAL mode, the grey screen with Apple logo (and spinning wheel) is shown for about 50 seconds. The device never shows the blue background or login window. It simply shuts down like the power was pulled.
    When booting in SAFE mode, the grey screen with Apple logo (and spinning wheel) is shown for about 1 minute 30 seconds. The blue background is shown and quickly transitions to the login windows. About 45 seconds after the login window is shown, the machine shuts down like the power was pulled.
    On the few occassions I logged in to take advantage of the 45 second safe mode window (before shutdown), I was *not* able to copy off my log files (in /log/var) to a thumb drive because the computer would not mount the USB device.
    When I peeked at the system's log file, I caught the tail end of "signature validation failed" for a bunch of hardware - from video to audio. I can only peek because the computer will shutdown before I have an opportunity to study anything in detail. The failed verifications may or may not be related to the shutdown - signature verfication might be disabled in safe mode; I simply don't know.
    It seems the world's most advanced operating system [tm] is performing the world's most epic failure. Any ideas to get this brick working again would be greatly appreciated.
    Jeffrey Walton
    Baltimore, MD, US

    Here's what I've found:
    (1) I cannot run Disk Utility because I don't have my install disk handy
    (2) I cannot run Repair Permissions because Apple does not make a separate ISO available to fix their mistakes
    (3) There does not appear to be a wat to back out updates (ie, no Add/Remove Programs)
    I was able to boot into safe mode and perform:
        > sudo bash
        $ chmod -R root /
    Amazingly, the command ran to completion. Unfortunately, it did not fix the problem. As soon as some spare cycles were available (interesting indeed!), the machine shutdown.
    +1 to Apple engineers for creating a broken patch
    +1 to Apple quality assurance for letting the junk out the door
    +1 to Apple, for not offering an ISO to fix a broken installation
    +1 to Steve, who has managed to keep his anti-trust lock on the hardware and broken software
    Great job, Apple

  • "logon time" between USR41 and security audit log

    Dear colleagues,
    I got a following question from customer for security audit reason.
    > 'Logon date' and 'Logon time' values stored in table  USR41 are exactly same as
    > logon history of Security Audit Log(Tr-cd:SM20)?
    Table:USR41 saves 'logon date' and 'logon time' when user logs on to SAP System from SAP GUI.
    And the Security Audit Log(Tr-cd:SM20) can save user's logon history;
    at the time when user logged on, the security audit log is recorded .
    I tried to check SAP GUI logon program:SAPMSYST several ways, however,
    I could not check it because the program is protected even for read access.
    I want to know about specification of "logon time" between USR41 and security audit log,
    or about how to look into the program:SAPMSYST and debug it.
    Thank you.
    Best Regards.

    Hi,
    If you configure Security Audit you can achieve your goals...
    1-Audit the employees how access the screens, tables, data...etc
    Answer : Option 1 & 3
    2-Audit all changes by all users to the data
    Answer : Option 1 & 3
    3-Keep the data up to one month
    Answer: No such settings, but you can define maximum log size.
    4-Log retention period can be defined.
    Answer: No !.. but you can define maximum log size.
    SM19/SM20 Options:
    1-Dialog logon
    You can check how many users logged in and at what time
    2-RFC login/call
    Same as above you can check RFC logins
    3-Transaction/report start
    You can see which report or transaction are executed and at what time
    (It will help you to analyise unauthorized data change. Transactions/report can give you an idea, what data has been changed. So you can see who changed the data)
    4-User master change
    (You can see user master changes log with this option)
    5-System/Other events
    (System error can be logged using this option)
    Hope, it clear the things...
    Regards.
    Rajesh Narkhede

  • How to monitor user logs,security logs,trace file,and performance monitori

    Hi guys,
    pls tel me how to monitor user logs,security logs,trace file,and performance monitoring.
    thanks
    regards
    kamal

    Hi,
    you can have a look in the Netweaver administration :
    http://<portal>:<port>/nwa
    Go to monitoring, Java system reports, etc..., you will find what you want.
    Fabien.

  • Secure.log and log rotation problems

    I had originally posted this in the Tiger section, but now finding the Unix section which I think would be able to help me more. here is the link to the post: http://discussions.apple.com/thread.jspa?threadID=1913487&tstart=0
    Also I am getting this in my system.log, I have googled it and cannot find anything that tells me what it is:
    Feb 19 18:54:34 SamiMac kernel[0]: m378d97c0 0
    some help on this would also be appreciated.
    Message was edited by: a Mac user

    The secure.log message is explained at the bottom of Spurious Permission errors in OS X 10.4.
    For your ipfw logs, check that /etc/periodic/weekly/500.weekly contains the line
    for i in ftp.log lookupd.log lpr.log mail.log netinfo.log hwmond.log ipfw.log ppp.log secure.log; do
    (although I don't know why it wouldn't) and then check this is actually being run by looking at /var/log/weekly.out. Try
    tail -10 /var/log/weekly.out
    Let us know what you see.
    I haven't seen that kernel message before

Maybe you are looking for

  • Investment order field is missing in origin tab of asset master (AuC)

    Dear Experts, While creating an asset master (AuC), the Investment Order field is not shown for the input, in the Origin Tab. Whereas for Asset master for the other Asset classes are showing this field for the input. Please advice how can I get this

  • Nokia N95 (CAN'T ABLE TO BROWSE WAP IN 3G)

    Dear Experts, i am facing a problem in 3G service in NOKIA N95. i am having the service of 3G when i will connect the internet via WAP it will connect but i cannot able to browse or open any web page and if i will discoonect the wap and try to connec

  • MIR6 (invoice overview) open document using MIR6

    Hi All, I am having problem to select the Document in the invoice overview: Invoice Document (MIR6) transaction code. I can open the document please if any one knows whatu2019s need to be done. Thanks

  • Business Connector vs. XI

    Hi to everyone! For your opinion wich integrator is better, Business Connector or XI? What will be the future of each one? How many companies are still using the Business Connector? Thanks a lot for your help!

  • Can you download CS6 on antother computer years apart?

    I purchased the CS6 disk years ago and my hard drive crashed. Is there still a chance that I can download the disk onto a new second computer, or the old computer that now has a new hard drive?