Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Auditing Account Lockouts

Status
Not open for further replies.

nevets2001uk

IS-IT--Management
Jun 26, 2002
609
GB
For a while now we've been auditing failed login attempts on our Domain Controllers but recently were asked about recorded lockouts of accounts.

I found that by enabling the success audit for the Audit Account Management setting we were able to ensure that future lockouts get recorded as 644 events in the event log, however this also induces many other events to be recorded, such as every time we ammend a group membership etc.

Is there a way to force to recording of account lockouts in the event log (or any other log) but to avoid recording all of the other success events?

Steve G (MCSE / MCSA:Messaging)
 
I don't believe you can restrict account management auditing to individual events with the event logging service, but there are some free filtering tools available. You can easily generate a report that filters for the event you're looking for.

Search for elogdmp.exe, dumpel.exe, or Event Comb.

All of these tools were parts of various Microsoft Resource Kits; I don't recall the exact years though.

If this is a big enough concern for your company there are several 3rd party utilties that offer a lot more than the basic filtering the reskit tools can provide.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top