Guest Rafael Posted August 28, 2007 Posted August 28, 2007 I'd be really grateful for some help please. I'm a newbie!! I have a Dell Latitude laptop running Windows XP Pro. The Security event log on this machine has hundreds of 'Success Audit' type entries. They are mainly events 528, 538, and 576 (Logon/Logoff, Privilege Use etc). When I say hundreds, I mean there appears to be an average of about 4 per minute under normal use. Whenever I have looked at the Security event log on other machines, 9 times out of 10 there's only one 'Success Audit' type entry there. I have looked at Control Panel --> Administrative Tools --> Local Security Policy --> Local Policies --> Audit Policies on the laptop. Everything is configured as 'No Auditing' with the exception of 'Audit account logon events' and 'Audit logon events'. These are set as 'Success, Failure' however, when I click on 'Properties' for each of these, the options to audit successes and / or failures are selected but greyed out and I cannot change them. To be honest, this is just about where I come unstuck although I have *tried* to do some research and I think this must be because there is a Domain Security Policy. I have Administrator access to the Domain Controller / Windows 2000 Server (SP4) but I don't know what to do now. The odd thing is that there are other machines in the Domain which don't have this intensive Security event logging. Any advice greatly appreciated. I am more than happy to provide whatever further information you need in order to help me resolve this. Thank you in advance.
Recommended Posts