Security Auditing Issue

Paperlantern

Platinum Member
Apr 26, 2003
2,239
6
81
I'm wondering if anyone here could help me out here. Ive got a 2003 Server as an active Domain Controller in our forest. We have a forwarder on this box forwarding log events to Splunk. I noticed that in Splunk i was not getting ANY Audit Failures, even when i tried to create them on purpose. Looking directly at the domain controller's Security Log, it also shows NOTHING but Success Audits. Confused, i went into active directory users and computers, right clicked on the top level of the domain, clicked properties, went to Windows Settings -> Security Settings -> Local Policies -> Audit Policy. There, Audit account logon events is set to Success, Failure. I was thinking maybe ONLY Success would have been checked, peventing the failures from showing, but its not, it IS set to audit both. So failures should at least show up. They do not, even when trying to access the box DIRECTLY from the console, attempt a log in, type the wrong password, NOTHING shows in the log. Not a single peep about the fact someone just failed to log in.

Am I missing something here? Am I in the wrong place to edit the policy properly? All research I've done shows that I am, and when i view thier videos or screen shots in thier examples, the failure audits happily populate into the log. On mine, Success, Success, Success, as far as the eye can see.

Halp!
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
You're doing this through Group Policy, right? via Default Domain Policy? You said that you have "Audit Account Logon Events" set to Success and Failure. What about "Audit Logon Events"? It's been a long time since I've read the documentation on these, but I just took a quick look at my GPO here and I have both of those enabled for Success and Failure.
 

Paperlantern

Platinum Member
Apr 26, 2003
2,239
6
81
Yes that is exactly where I'm looking. That isn't enabled on mine, I thought it just meant it will log the event to the local box that the person tried to log onto, but not necessarily report it to the domain controller. I could have misunderstood the explanation of course and I will turn that on now to see if that make a difference. Will report back in a little while. Thanks.
 

Paperlantern

Platinum Member
Apr 26, 2003
2,239
6
81
Still nothing but Success Audits. i even tried setting both to Failures ONLY. Still successes come in several at a time every few seconds.
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
Maybe check your Default Domain Controllers Policy?

You could also use the Group Policy Modeling wizard to view what policies are set on the Domain Controllers OU and what GPO is applying policy.

Maybe go into the Local Security Policy (secpol.msc) on the DC and see what Audit settings are enabled?
 

phoenix79

Golden Member
Jan 17, 2000
1,603
0
0
Also, make sure you're refreshing your GP on the machines you're testing and logging on once you change the GP. If you don't and they don't take effect all your testing is worthless
 

Firetower

Senior member
Jul 15, 2003
447
0
0
refresh group policy on a node then run rsop.msc see where the group policy settings are coming from. (local or domain).

Make sure you have the policy linked properly.
 

stlcardinals

Senior member
Sep 15, 2005
729
0
76
Also it is a good idea to not change the default domain policy, but make a new gpo to implement your changes on.
 

rasczak

Lifer
Jan 29, 2005
10,453
22
81
is inheritance blocked? (little blue ! will indicate blocked inheritance in a policy) two, are the links enabled?

install GPMC if not installed already to get a better idea of how your GP is setup.

Also, I absolutely agree with stlcardinals. add gpo's by creating new policies instead of editing your baseline gpo. this way you can troubleshoot better bad policy settings.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |