Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Security Events Log for addition of members into GUESTS security group

Status
Not open for further replies.

libroos

Technical User
Feb 16, 2001
195
SG
Dear all,

If someone add members into security groups, e.g. GUESTS or ADMINISTRATORS, what would be the logged Windows Security event ids in the Windows 2000 Server?

What are the typical description of the security logs?

R there any good log analyzer program?

Regards,
libroos
 
If you have auditing enabled you should see the following events appearing;
631 Security enabled global group created
§ 632 Security enabled global group member added
§ 633 Security enabled global group member removed
§ 634 Security enabled global group deleted
§ 635 Security disabled local group created
§ 636 Security disabled local group member added
§ 637 Security enabled local group member removed
§ 638 Security enabled local group deleted
§ 639 Security enabled local group changed
§ 641 Security enabled global group changed

Hope this helps
 
I've checked the Servers, but could not find it. I guess it could be that the auditing settings are not enabled.

Where do I enable detailed auditing settings?

R there any recommended hardening steps?
 
In local security policy (for servers not on the domain) or group policy --> Security Settings-->Local Policy-->Audit policy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top