Link to home
Start Free TrialLog in
Avatar of snyderkv
snyderkv

asked on

DC permissions for event log

Im having a hard time finding out how to let a normal user (non domain admin) to view the event logs on domain controllers.

I know there is a security and audit log in the secpol.msc local security policy but didn't do much testing. I know that will also allow install of patches aassuming they have local logon rights.

What security group or local security policy would allow for non domain admins to view event logs on Domain Controllers?
ASKER CERTIFIED SOLUTION
Avatar of Ram Balachandran
Ram Balachandran
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of snyderkv
snyderkv

ASKER

Is the first link incorrect? It explains simple file sharing. I don't tink that has anything to do with allowing users to view event logs on DC's. I'm still a little lost. What about allowing users to log on locally to DC's with no rights except to view security logs? I think that would be more secure because they can view but not erase logs.