Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Windows Server 2003 Read Only Event Log viewing

Posted on 2008-10-06
Last Modified: 2013-12-05
I am trying to allow a group of users in a specific OU to be able to have 'Read Only' access to 4 Windows Server 2003 Servers to allow them to diagnose problems. Is this possible without giving them access to the Servers either locally or remotely.
Question by:amlloyd
  • 2
  • 2

Accepted Solution

placebo69a earned 500 total points
ID: 22648523
Hi there!
Yes, it is possible to give users either local or remote read only access to your server's event log. For remote access the users must have logged in to the server at least once so that their SID is in the server's registry.
The process involves editing a registry value called CustomSD for each of the logs' registry keys  (app, sec, sys etc.) found under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog.
The CustomSD value contains the permissions in SDDL form, each entry looking something like this:
The first part is whether to allow (A) or deny (D) access, followed by a couple of semi-colons.
The second part is the level of access. Use this table and add up the values to determine access. If you want read only access this value should be 4, full access is the sum of all the values - 7.
  • Read access - 4
  • Write access - 2
  • Clear access - 1
The third and last part (preceded by 3 semi-colons) is the user's SID. Not sure how to determine a user's SID? There are plenty of small applications out there to do it for you. Here's one. It's a vbscript that pulls out the sAMAccountName for every security principle on the machine. That's the SID you want to give the permission to.
Let me know if this helps. :)


Author Comment

ID: 22650390
Will I have to reboot the Server once I have changed the entries in the Registry?

Expert Comment

ID: 22675136
Yes, a reboot is required for the changes to take effect.

Author Closing Comment

ID: 31623590
Many thanks for your support in this matter.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip is around source server preparation. No migration is an easy migration, there is a…
Have you considered what group policies are backwards and forwards compatible? Windows Active Directory servers and clients use group policy templates to deploy sets of policies within your domain. But, there is a catch to deploying policies. The…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question