Results 1 to 3 of 3

Thread: Event Viewer Driving Me Mad (SBS 2011)

  1. #1
    HEXUS.social member Allen's Avatar
    Join Date
    Nov 2003
    Location
    Brighton
    Posts
    8,536
    Thanks
    363
    Thanked
    262 times in 168 posts
    • Allen's system
      • Motherboard:
      • ASUS Maximus VIII Gene
      • CPU:
      • Intel Core i5 6600K
      • Memory:
      • 2 x 8GB Kingston HyperX Predator DDR4-3000
      • Storage:
      • 256GB Samsung 950 PRO NVMe M.2 (OS) + 2 x 512GB Samsung 960 EVO in RAID 0 (Games)
      • Graphics card(s):
      • ASUS ROG Strix GeForce GTX 1080 Ti OC
      • PSU:
      • XFX P1-650X-NLG9 XXX 650W Modular
      • Case:
      • Fractal Design Node 804
      • Operating System:
      • Windows 10 Home 64-bit
      • Monitor(s):
      • 27" BenQ XL2730Z + 23" Dell U2311H
      • Internet:
      • Virgin Media 200Mbps

    Event Viewer Driving Me Mad (SBS 2011)

    Hi guys, need a little help here if possible. I have an issue that is driving me mad and I am unsure how to fix it, despite me spending many hours trying to research it. TLR at the bottom.

    A quick run down of what is happening.

    We have a device on the network which integrates with AD to lookup user information whenever they do something on the network. Every time the device connects to AD an audit success for logon (4624), special logon (4672), credential validation (4776) and logoff (4634) are registered in the security event log. Even with a reasonably low amount of network usage this is currently flooding the event log with about 20 entries every second, meaning that at it's current maximum log size of 128MB, it is filled in about 2.5 hours. This makes tracking down real security issues an impossibility.

    Now, I am aware that I can either increase the maximum log size (not really the answer) or stop logging these event IDs completely (not an option in my mind as they are otherwise useful), but what I have failed to find out is if I can stop a particular device from being logged in the security event log.

    I have contacted the device manufacturer and they advise that this issue is not in their domain (pun not intended I assume) and my Google-Fu has let me down in trying to find the answer I need.

    So, the actual question and the TLR version:

    Can I limit logging in Event Viewer for a particular device on the network, rather than limiting logging for an entire Event ID which would otherwise be useful?

    A serious amount of kudos and cookies (virtual ones) to anyone who can help me!

  2. #2
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    653 times in 482 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Event Viewer Driving Me Mad (SBS 2011)

    From my bookmarks (when I faced something similar on our SBS 2011e server);

    http://social.technet.microsoft.com/...serversecurity

    and

    http://social.technet.microsoft.com/...serversecurity
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  3. #3
    HEXUS.social member Allen's Avatar
    Join Date
    Nov 2003
    Location
    Brighton
    Posts
    8,536
    Thanks
    363
    Thanked
    262 times in 168 posts
    • Allen's system
      • Motherboard:
      • ASUS Maximus VIII Gene
      • CPU:
      • Intel Core i5 6600K
      • Memory:
      • 2 x 8GB Kingston HyperX Predator DDR4-3000
      • Storage:
      • 256GB Samsung 950 PRO NVMe M.2 (OS) + 2 x 512GB Samsung 960 EVO in RAID 0 (Games)
      • Graphics card(s):
      • ASUS ROG Strix GeForce GTX 1080 Ti OC
      • PSU:
      • XFX P1-650X-NLG9 XXX 650W Modular
      • Case:
      • Fractal Design Node 804
      • Operating System:
      • Windows 10 Home 64-bit
      • Monitor(s):
      • 27" BenQ XL2730Z + 23" Dell U2311H
      • Internet:
      • Virgin Media 200Mbps

    Re: Event Viewer Driving Me Mad (SBS 2011)

    Thanks for the links. I have had a thorough read through but unfortunately it seems like my specific question isn't answered.

    However, it has prompted me to ask my own question on the TN forums, hopefully someone there will be able to reply.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •