1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Security log full

Discussion in 'Windows Home Server' started by DD, May 11, 2009.

  1. DD

    DD Guest

    I have disabled the audit log - not define in domain security policy, but
    some of the user stiil getting the security log full and can't loginto the
    DC. i checked the evernt security, it sill logged the previledge use. any
    idea why ?

    what is the command to run the gpupdate /force without login administrator
    id ?
     
  2. DD

    DD Guest

    i tried to run the force/update fromthose pcs, not looks like it din't update.

    can someone help ?

    "DD" wrote:

    > I have disabled the audit log - not define in domain security policy, but
    > some of the user stiil getting the security log full and can't loginto the
    > DC. i checked the evernt security, it sill logged the previledge use. any
    > idea why ?
    >
    > what is the command to run the gpupdate /force without login administrator
    > id ?
     
  3. Hello DD,

    What security log are you talking about, local machines or domain controller?
    Did you save and clear the security log?

    Best regards

    Meinolf Weber
    Disclaimer: This posting is provided "AS IS" with no warranties, and confers
    no rights.
    ** Please do NOT email, only reply to Newsgroups
    ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


    > I have disabled the audit log - not define in domain security policy,
    > but some of the user stiil getting the security log full and can't
    > loginto the DC. i checked the evernt security, it sill logged the
    > previledge use. any idea why ?
    >
    > what is the command to run the gpupdate /force without login
    > administrator id ?
    >
     
  4. Hank Arnold

    Hank Arnold Guest

    DD wrote:
    > I have disabled the audit log - not define in domain security policy, but
    > some of the user stiil getting the security log full and can't loginto the
    > DC. i checked the evernt security, it sill logged the previledge use. any
    > idea why ?
    >
    > what is the command to run the gpupdate /force without login administrator
    > id ?


    What log file are we talking about? Are you talkign about the Security
    Event Log? If so, then configure it to increase the size and to
    overwrite events as needed...

    My next question is why do you have users logging into the DC? THis is
    normally not a good idea. It really should only be admins....

    --

    Regards,
    Hank Arnold
    Microsoft MVP
    Windows Server - Directory Services
    http://mypcassistant.blogspot.com/
     
  5. DD

    DD Guest

    local security log.yes, we clear the log, but next day it full again. i dont
    want to go to individual pc to set the log to overwrite. i have disabled the
    audit log from domain policy, but it doesn't apply to some of the user pc.



    "Meinolf Weber [MVP-DS]" wrote:

    > Hello DD,
    >
    > What security log are you talking about, local machines or domain controller?
    > Did you save and clear the security log?
    >
    > Best regards
    >
    > Meinolf Weber
    > Disclaimer: This posting is provided "AS IS" with no warranties, and confers
    > no rights.
    > ** Please do NOT email, only reply to Newsgroups
    > ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
    >
    >
    > > I have disabled the audit log - not define in domain security policy,
    > > but some of the user stiil getting the security log full and can't
    > > loginto the DC. i checked the evernt security, it sill logged the
    > > previledge use. any idea why ?
    > >
    > > what is the command to run the gpupdate /force without login
    > > administrator id ?
    > >

    >
    >
    >
     
  6. DD

    DD Guest

    local security log, i have more than 1k pcs, do want to go to individual pc
    to adject the security log setting. i disabled the audit log from domain
    policy, it should apply to the user pc, somehow it does not apply. the log
    file growth very fast.

    User have to login to domain.


    "Hank Arnold" wrote:

    > DD wrote:
    > > I have disabled the audit log - not define in domain security policy, but
    > > some of the user stiil getting the security log full and can't loginto the
    > > DC. i checked the evernt security, it sill logged the previledge use. any
    > > idea why ?
    > >
    > > what is the command to run the gpupdate /force without login administrator
    > > id ?

    >
    > What log file are we talking about? Are you talkign about the Security
    > Event Log? If so, then configure it to increase the size and to
    > overwrite events as needed...
    >
    > My next question is why do you have users logging into the DC? THis is
    > normally not a good idea. It really should only be admins....
    >
    > --
    >
    > Regards,
    > Hank Arnold
    > Microsoft MVP
    > Windows Server - Directory Services
    > http://mypcassistant.blogspot.com/
    >
     
  7. Hello DD,

    Please post the setting's you have configured. Are the machines located in
    the OU where the policy is linked to? Did you run rsop on the client to see
    if the policy is applied correct?

    Best regards

    Meinolf Weber
    Disclaimer: This posting is provided "AS IS" with no warranties, and confers
    no rights.
    ** Please do NOT email, only reply to Newsgroups
    ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


    > local security log.yes, we clear the log, but next day it full again.
    > i dont want to go to individual pc to set the log to overwrite. i have
    > disabled the audit log from domain policy, but it doesn't apply to
    > some of the user pc.
    >
    > "Meinolf Weber [MVP-DS]" wrote:
    >
    >> Hello DD,
    >>
    >> What security log are you talking about, local machines or domain
    >> controller? Did you save and clear the security log?
    >>
    >> Best regards
    >>
    >> Meinolf Weber
    >> Disclaimer: This posting is provided "AS IS" with no warranties, and
    >> confers
    >> no rights.
    >> ** Please do NOT email, only reply to Newsgroups
    >> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
    >>> I have disabled the audit log - not define in domain security
    >>> policy, but some of the user stiil getting the security log full and
    >>> can't loginto the DC. i checked the evernt security, it sill logged
    >>> the previledge use. any idea why ?
    >>>
    >>> what is the command to run the gpupdate /force without login
    >>> administrator id ?
    >>>
     

Share This Page