Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Account lockout not showing in Security Event Log

Status
Not open for further replies.

sharte

MIS
Oct 18, 2000
3
0
0
CA
I am running WIndows 2003 Server with 2 domain controller's. When a users account is locked it doesn't get wrote to the security log on either server. All the audit settings are correct. I need to use these lockouts for my Active Directory manager reports!!!

Please Help!!
 
Increase the size of the logs. You may also need to review the settings so that events are not overwritten. Otherwise if you have configured auditing to audit account logon and logon events (success / failure) the lockouts will be written to the security log.
 
I have increased the size of the logs, cleared the old logs and ensured that all auditing is turned on. I locked out a user by typing the password incorrectly and still no event log to show the lockout!!
 
Can you share what you have configured in the Default Domain Policy for the auditing?
 
You should have:

Audit account logon events: success/failure
Audit logon events: success/failure

The machine that you are trying from must also be a member of your domain and the GPO must be applying to it.

You will only see the account lockout information on your Domain Controllers - not on the PC that you locked the account on. Maybe this is your error.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top