Link to home
Start Free TrialLog in
Avatar of lapucca
lapucca

asked on

How do I trun on the Security log so I can see the event loggin in the Event Viewer?

I'm using Windows 2000 server.  Right now, there is no entry at all in my security log.

Thanks.
ASKER CERTIFIED SOLUTION
Avatar of jburgaard
jburgaard

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of lapucca
lapucca

ASKER

I followed the instruction of the 1st link but it's still not working and in  the Local Security Policy rihgt panel it still says "No auditing" in the "Effective Setting" column.  Why is that so?  
Also, I am in a domain, and the 1st link has a note about his as follow.  So how can I change that if I need to?  Thanks.
NOTE: If you are a member of a domain, and a domain-level policy is defined, domain-level settings override the local policy settings.


1. Log on to Windows 2000 with an account that has Administrator rights. If you want to grant other users the rights to set auditing, see the "How to Enable Another Account to Configure Auditing" section in the "Reference" section of this article.
2. Ensure that the Group Policy snap-in is installed; if it is not installed, follow the directions in the "How to Install the Group Policy Snap-in" section in the "References" section of this article to install it.
3. Click Start, point to Settings, and then click Control Panel.
4. Double-click Administrative Tools.
5. Double-click Local Security Policy to start the Local Security Settings MMC snap-in.
6. Double-click Local Policies to expand it, and then double-click Audit Policy.
7. In the right pane, double-click the policy that you want to enable or disable.
8. Click the Success (An audited security access attempt that succeeds) and Fail (audited security access attempt that fails) check boxes for logging on and logging off. For example, with this setting, a user's successful attempt to log on to the system is logged as a Success Audit event. If a user tries to access a network drive and fails, the attempt is logged as a Failure Audit event.
Avatar of lapucca

ASKER

Got it, I had to do it through Group Policy.  Thanks.