Re: [logs] Windows Event Log Analysis

From: H C (keydet89at_private)
Date: Fri Jan 03 2003 - 10:35:51 PST

  • Next message: Rainer Gerhards: "RE: [logs] Syslog payload format"

     
    > I discovered yesterday that Windows does not always
    > log process creation and termination.
    
    Not by default, no.  
    
    I read through the rest of your post, and noticed one
    glaringly absent piece of information...what your
    auditing configuration looked like.  You never
    specified whether or not you had Process Tracking
    (both success and failure events) enabled in the
    EventLog configuration.  It seems that you do have
    Object Access enabled, but perhaps not Process
    Tracking.
    
    I only point out the above b/c I don't want to err and
    assume that you do have the necessary logging enabled.
    
    
    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Fri Jan 03 2003 - 18:55:49 PST