Link to home
Start Free TrialLog in
Avatar of rbosco020475
rbosco020475

asked on

Access to event viewer for non server users

I have a windows 2003 domain that has a handful of application servers in it. I am looking to give my admins group the ability to read from the event viewer for troubleshooting remotely. These users cannot have an account on the server and do not have admin level permissions of any kind.

Is there a way to grant them the ability to connect to the event logs on a machines remotely (using event viewer on another server) without making them a local admin account/user permissions? They only need to be able to connect to the log files and read from them. They do not have the need to make any changes.

Thanks

Avatar of Pber
Pber
Flag of Canada image

Yes there is.  It isn't the most simplest procedure, but this will do it.  We do this with our Domain Controllers and allow the exchange admins to view logs on the DC's without giving them domain admin access.

http://support.microsoft.com/default.aspx/kb/323076
They could use Manage and connect to the remote computer, without admin privledges they will not be able to see the security logs but the other logs should be visible. In order to view security logs they have to have administrator rights on the box.

Right click My computer-->Manage, Right Click Computer Management-->connect to another computer.

See this as well: http://www.microsoft.com/technet/security/guidance/serversecurity/tcg/tcgch06n.mspx

specifically: Delegating Access to the Event Logs

ASKER CERTIFIED SOLUTION
Avatar of Pber
Pber
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial