Unable to record/save security (or any) event log files....

multiband8303

Senior member
Aug 8, 2005
593
0
0
Here's the deal get this error message whenever I attempt to save my event viewer files..

Unable to save event log to file (\\servername\instance)- A required privilege is not held by this client...

smells like a permission problem right?...not so fast boys...
(reminder I am logged as domain admin)

Local security policy - user rights assignment, administrators is set....fine, I set it to domain admins, and also make domain admins run as operating system....

(sidenote, this is a terminal server with citrix....I am able to do this on my file server but neither of my terminal servers....)

So I think...may be a GPO issue...considering my Terminal Servers are in a different OU then my File server....But everything looks in order...

HELP AN IDIOT OUT! PLEASE AND THANK YOU IN ADVANCE!
 

multiband8303

Senior member
Aug 8, 2005
593
0
0
Not a single person has a clue? I have done my research on this, any help would be greatly appreciated...
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
To clarify:
this feature/function (export event log to file) works fine when you're using TSclient to connect to the file server, and running eventviewer there.
this feature/function does NOT work when you're using TSClient to connect to a Citrix server (in a different OU), and running eventviewer there.

Sounds to me like a Citrix lock-down sort of thing. IIRC, Citrix offers considerably more lockdown capabilites than TS does.
 

jimdwa6538

Junior Member
Jul 19, 2006
8
0
0
I'm having an identical issue on Win2003 as well. Same error:
Unable to save event log to file (\\servername\instance)- A required privilege is not held by this client
As the original poster.

I am unable to save the event log locally as an .evt file. I can save as a .csv or .txt either locally or on a share. I have tried through the Event Viewer on my workstation (connect to another computer) and also through remote desktop. It didn't work from the console either but it is attached to a ethernet KVM switch so it might be emulating remote access.

The servers I have the problem with are not a member of any OUs other than domain computers and they are effected by the default domain policy only (as far as I can tell) the only settings in the event viewer section of the policy is to set the size of the log and retention to overwrite when full.

The size set in the GPO is overridden locally by the MMC snap-in settings. All of the log files are full. And I can't use NTbackup to save them either. The backup kicks off normally but the .evt files never get copied. (could be a restricted file type. I didn't check)
 

jimdwa6538

Junior Member
Jul 19, 2006
8
0
0
Got it. Solved my own problem. I had to define the "Allow logon through terminal services" policy in the Default Domain Policy GPO and add the users and groups that needed access. You would have to do it to whatever GPO is enforced in your AD. FYI the path to that policy setting is: Default Domain Policy>Computer Configuration>Windows Settings>Security Settings>Local Policies>User Rights Assignment>Allow logon through Terminal Services Right-click>Properties>Brows to user or group
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |