What caused the Windows 2008R2 Security event discarded

Dear Support team,
I have a windows 2008 R2 server, The security events didn't recorded from last year.
1. The maximum log size set to 100 MB, But the log file is 300 MB.  The retention was set to "archive the log when full,do not overwrite events".
2.  Below last entry security log show the registry key that i modified at that time. After i modify the registry value all of the security event were discarded
A registry value was modified.
Subject:
                Security ID:                              domain\userid
                Account Name:                        userid
                Account Domain:                     domain
                Logon ID:                                0x2c202074
Object:
                Object Name:                           \REGISTRY\MACHINE\SYSTEM\ControlSet001\services\eventlog\Security
                Object Value Name: Retention
                Handle ID:                               0x100
                Operation Type:                       Existing registry value modified
Process Information:
                Process ID:                               0x129c
                Process Name:                          C:\Windows\regedit.exe
Change Information:
                Old Value Type:                       REG_DWORD
                Old Value:                                0
                New Value Type:                      REG_DWORD
                New Value:                              4294967295
3. As i know,The Windows Event Log supersedes the Event Logging API beginning with the Windows Vista operating system. Here is the KB link:  http://msdn.microsoft.com/en-us/library/windows/desktop/aa385780(v=vs.85).aspx?ppud=4
And the registry key which i modified at the before ( \REGISTRY\MACHINE\SYSTEM\ControlSet001\services\eventlog\Security\retention )  Seems only apply to Event logging  for Windows 2003 and prior system. 
Here is the KB link:  http://msdn.microsoft.com/en-us/library/windows/desktop/aa363648(v=vs.85).aspx
May i know what is the reason cause security event discarded ?
Does the retention setting at Registry still working at windows 2008?
Thanks very mush.
Randy

The new methods are via GPO described here.
http://technet.microsoft.com/en-us/library/cc722385(v=WS.10).aspx
http://blogs.technet.com/b/askds/archive/2008/08/12/event-logging-policy-settings-in-windows-server-2008-and-vista.aspx
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows]
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

Similar Messages

  • What is the diffrence between sap events and application events

    Hi all,
    what is the diffrence between sap events and application events.Can any one tell me with examples.
    regards,

    Hi,
    Look at this,
    <b>System Events (Default)</b>
    The event is passed to the application server, but does not trigger the PAI. If you have registered an event handler method in your ABAP program for the event (using the SET HANDLER statement), this method is executed on the application server.
    Within the event handler method, you can use the static method SET_NEW_OK_CODE of the global class CL_GUI_CFW to set a function code and trigger the PAI event yourself. After the PAI has been processed, the PBO event of the next screen is triggered.
    The advantage of using this technique is that the event handler method is executed automatically and there are no conflicts with the automatic input checks associated with the screen. The disadvantage is that the contents of the screen fields are not transported to the program, which means that obsolete values could appear on the next screen. You can work around this by using the SET_NEW_OK_CODE method to trigger field transport and the PAI event after the event handler has finished.
    <b>Application Events</b>
    The event is passed to the application server, and triggers the PAI. The function code that you pass contains an internal identifier. You do not have to evaluate this in your ABAP program. Instead, if you want to handle the event, you must include a method call in a PAI dialog module for the static method DISPATCH of the global class CL_GUI_CFW. If you have defined an event handler method in your ABAP program for the event (using the SET HANDLER statement), the DISPATCH method calls it. After the event handler has been processed, control returns to the PAI event after the DISPATCH statement and PAI processing continues.
    The advantage of this is that you can specify yourself the point at which the event is handled, and the contents of the screen fields are transported to the application server beforehand. The disadvantage is that this kind of event handling can lead to conflicts with the automatic input checks on the screen, causing events to be lost.
    Hope u understood.
    Thanks&Regards,
    Ruthra.R

  • HT1461 Win 7 set up and running OK,but after go back from OSX the wireless net work stuck at identification cause the window working without Internet.Can we fix it or I must use Windows off line all the time? I already contact Microsoft 2 times for activa

    Win 7 set up and running OK,but after go back from OSX the wireless net work stuck at identification cause the window working without Internet.Can we fix it or I must use Windows off line all the time?
    I already contact Microsoft 2 times for activations.Hope I can fix from Apple instead.

    Ok....Got "Problem 2 and 4" solved....still trying to figure out this pop up everytime I click something...it's crazy how fast the pop up blinks...maybe once or 3 blinks then nothing till you close the window, then pop up then disappears...then click something
    else and pop up then gone....never seen this before...ive seen it when you tried to get online which turned out to be a virus on a customers cpu I worked on some years ago, I think it has something to do with the deleted files that I spoke of on last
    post...I notice it does it on start up as well.....think something is trying to install but not sure. Need to figure out where the appdata or start up folder and see whats in there....maybe it's in there.......so I might wait to see how it acts in the next
    couple days for "Problem 1"...but other than that it's running like a champ...so right now I just want to get the pop up windows to stop........thx again for everyone's help on this.
    John

  • What causes the Missing or invalid version of SQL library PSORA (200,0)?

    What causes the Missing or invalid version of SQL library PSORA (200,0) in PeopleTools 8.51 Application Designer?

    Could be several things. Bad path, bad version, etc. give us details on your client install. What Oracle client do you have installed. App Designer is 32 bit. If you installed the 64 bit client you might get this error. What OS are you using. PeopleTools version? guessing 8.51 from your other post.

  • After sending a picture or message in "Message", what causes the "send" button to grey out?

    After sending a picture or message in "Message", what causes the "send" button to grey out?

    Restore your iPad to the factory settings.

  • I have a Mac late 06 with lion and what to know what is the best protection/security software to get, Mc Fee or Norton or...

    I have a Mac late 06 with lion and want to know what is the best protection/security to get, Mc Fee, or Norton,or...

    None of the above.
    Norton in particular is anathema.
    You have Apple's Xprotect system built-in. malware definitions are updated at each Security Update.
    If you feel the need for belt & braces, ClamXAV is the (free) tool of choice.
    Your best security is still the stuff between your ears. Don't click on pop-up links telling you need a new codec or (especially) Flash Player. Use your common sense and you'll stay ahead of the industry.

  • What is the best internet security for mac

    what is the best internet security for mac

    You may find this User Tip on Viruses, Trojan Detection and Removal, as well as general Internet Security and Privacy, useful: The User Tip seeks to offer guidance on the main security threats and how to avoid them.
    https://discussions.apple.com/docs/DOC-2435

  • What causes the picture to download on my device

    what causes the picture to download on my device? such as I have 1000k pictures sync at icloud.com and I am just viewing them on my phone. What prompts it to download to my phone?

    Download what?

  • What is the windows server 2013 license version than I need to install workflow manager 1.0

    what is the windows server 2013 license version than I need to install workflow manager 1.0?
    enterprise or standard? can I install it on datacenter?
    please provide me with the reference.
    thanks

    Workflow Manager will work with either SharePoint Enterprise or Standard.  It doesn't work well with Foundations since it depends on User Profiles to pass user identity to the workflow.  And yes you can install it on Windows Server datacenter edition.
     Here are the supported platforms for installation
    http://msdn.microsoft.com/en-us/library/jj193487(v=azure.10).aspx
    This article talks about integration with SharePoint and states that Foundation is not supported, but it doesn't differentiate between the Server editions, so any edition will do.
    http://technet.microsoft.com/en-us/library/jj658588.aspx
    Paul Stork SharePoint Server MVP
    Principal Architect: Blue Chip Consulting Group
    Blog: http://dontpapanic.com/blog
    Twitter: Follow @pstork
    Please remember to mark your question as "answered" if this solves your problem.

  • The bookmark tab went from the right side to the left side. I did not change that. what cause the change from the right side to the left side?

    The bookmark tab went from the right side to the left side. I did not change that. what cause the change from the right side to the left side? Also the the Mozilla Firefox tab on the upper left hand corner changed.
    Its was a red colored tab and now its blue in color. I did not change any thing!

    Hey jimmiet,
    There were some recent ui changes around the downloads manager. What version where you on before? Anyway, you can customize things in Firefox really easily. Take a look at [[Customize Firefox controls, buttons and toolbars|this article on customizing Firefox]] for details. Should be a piece of cake to move the bookmarks button.
    As for the color of the button, you might be in [[Private Browsing - Browse the web without saving information about the sites you visit|Private Browsing]] mode. That changes the color of the button from orange to a purplish color.
    Matt

  • What causes the display to develop darkened areas?

    What causes the display to develop darkened areas?

    Have you dropped the iPad?
    Try this  - Reset the iPad by holding down on the Sleep and Home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons. (This is equivalent to rebooting your computer.) No data/files will be erased. http://support.apple.com/kb/ht1430
     Cheers, Tom
    BTW - You don't need to double post.

  • HT201401 What causes the iPhone 4S to shut down to a black screen when it has full power?

    What causes the iPhone 4S to shut down to a black screen when it has full power? I have cleared the open icons and it works for one day then shuts down again.

    Software hiccup, glitch or maybe faulty battery. Restore iPhone with iTunes on computer. See if this helps. If still problem that you think is serious enough to fix, all iPhone 4S have full Warranty. Make Genius Reservation and take iPhone to Apple for resolution.

  • What causes the rainbow swirling icon that locks a program such as address book?

    What causes the rainbow swirling icon that locks a program such as address book? And how do I get out of it?

    The Finder is just assigning the wrong kind and icon to what I presume are plist files. Often rebuilding the Launch Services will cure this, but sometimes Finder gets a strange bee in its bonnet about some particular combination of characteristics and what they mean, and it can't be dissuaded. Unless you are opening plist files, and get really annoyed when you double click one and Address Book launches and announces "wrong type of file" you can just ignore it. In my own ~/Library/Prefences folder plists are generally labeled correctly, probably because I have them assigned to open with Apple's own Property List Editor. But there are some other preferences that Finder has decided are something altogether different than what they are: WingNuts Prefs and Saved Games are both believed to be Eudora preferences; a whole batch of other prefs from a dozen differenct programs are described as TextWrangler preferences, and there's a another group thought to be Unix Executables. As long as the program they belong to isn't having a problem finding and writing to them, don't worry about it.
    Francine
    Francine
    Schwieder

  • What are the main sap script events and their functionality and usage?

    what are the main sap script events and their functionality and usage?

    Hi,
    Inside the Script, there are events like Top of Page, End of page etc.
    Please elaborate about your requirement.
    Best regards,
    Prashant

  • What is the use of security pathces or cpu patches?

    Hi
    All,
    What is the use of security pathces or cpu patches?
    Thanks,
    Vishal

    Basically, Security patches keep your system secure from known expoits which could compromise your database should someone try to hack it. You don't have to put these patches on but you do need to assess the risk of not patching by checking what the security patch patches and deciding whether you are exposed or not. If you are unsure, then I'd recommend you patch.
    CPU patches are Critical Patch Updates that are issued quarterly. These are a mix of security patches and bug fixes. The same applies - you don't have to patch but it is worth taking a look at what is patch and making some assessment of how exposed you might be if you don't.
    Be warned, though. If you hit a problem and need Oracle's help, then Oracle support may insist that you are patched to the latest patchsets before they will assit with your issue (assuming the patch doesn't fix the issue).
    One word of advice would be that if you do decide to patch, patch your test environment first and make sure everything works normally afterwards, just in case the patch introduces a new issue for your environment - this is rare but I have seen it happen.
    Cheers,
    R

Maybe you are looking for

  • Can not get mail and  messages from old phone to my new phone

    can not get my mail and text messages transferred from my old Verizon Droid x2 to my LG Optimus  what's the process

  • More than 2GB of RAM?

    I have a 20"2Ghz iMac ALS with 2GB of RAM. Can I upgrade to 4GB? Thank you.

  • How can I add a group within Contacts

    How can I add a group within my Contacts list?

  • Order Confirmed - No Order Found

    I am still waiting on an outcome to this, I have not received an email response.  I do have a case number for this but I am unable to call during business hours today to follow up.  I have a copy of my order confirmation from the website but the orde

  • I want to see the apple company

    Hello colleagues, I am sorry I do not really do not know English u have no problem your iphone. Iphone super company my name Dilshod from Uzbekistan I am the master sews phone and unlock do. really want sidetracked company applets there any chance th