Solved

Configure Event Viewer Changes

Posted on 2009-07-03
4
347 Views
Last Modified: 2012-05-07
I have a couple of SBS 2003 and also a couple of SBS 2008 servers. When I see an event id of 529 which is "Unknown user name or bad password" I then want to know if a login was sucessful. Can I set this up to show in the event viewer or some other easy way? Also can I set a threshold so that I will only see a sucessful logon if there are more than x number of bad login attempts?
0
Comment
Question by:LostInWindows
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 18

Accepted Solution

by:
Don S. earned 175 total points
ID: 24772543
Yes and no.  You can change the audit policy to include successful login attempts.  However, you can not descriminate which successful attempts are included.  It's either ALL successful or NO successful (which is the default).  If you want to filter the logs better than Windows does natively, you would need to get a 3rd party log viewing program - of which there are many.
0
 
LVL 1

Author Comment

by:LostInWindows
ID: 24772730
Can you please provide the names of some 3rd Party log programs that are worthwhile?
Thanks
0
 
LVL 8

Assisted Solution

by:jako
jako earned 75 total points
ID: 24778463
we, for instance use SawMill (http://www.sawmill.net/) which I can heartily recommend.

You can, of course, with a little PowerShell and ActivePERL magic accomplish all the required functionality with no need to shell out the dough ;)
0
 
LVL 1

Author Closing Comment

by:LostInWindows
ID: 31599562
Thanks for the help!
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Many old projects have bad code, but the budget doesn't exist to rewrite the codebase. You can update this code to be safer by introducing contemporary input validation, sanitation, and safer database queries.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question