Announcement

Collapse
No announcement yet.

Active Directory Audit

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Active Directory Audit

    Hello.
    I need your help. How does Active Directory react to error or overflow of the security log?
    Thank you.

  • #2
    Other copy of this thread deleted from Server forum

    It depends on what you want to do - there are options to overwrite (circular logging) or to "crash on audit fail" (shut down the PC except to clear logs
    Tom Jones
    MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
    PhD, MSc, FIAP, MIITT
    IT Trainer / Consultant
    Ossian Ltd
    Scotland

    ** Remember to give credit where credit is due and leave reputation points where appropriate **

    Comment


    • #3
      Ossian,
      shut down the AD Controller or all computers in AD? Is there the warning of error or overflow of the security log?

      Comment


      • #4
        I want to know what is happened to computers in domain if the AD Controller are crashed?

        Comment


        • #5
          Shut down the computer which has the policy applied and the logs fill up. You will need to monitor log size and archive contents regularly

          If no domain controllers are available, cached credentials can be used (if enabled) or logons cannot be processed. Servers may not allow cached credentials, so you do not want this to happen.
          Tom Jones
          MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
          PhD, MSc, FIAP, MIITT
          IT Trainer / Consultant
          Ossian Ltd
          Scotland

          ** Remember to give credit where credit is due and leave reputation points where appropriate **

          Comment

          Working...
          X