Solved

Configure Event Viewer Changes

Posted on 2009-07-03
4
314 Views
Last Modified: 2012-05-07
I have a couple of SBS 2003 and also a couple of SBS 2008 servers. When I see an event id of 529 which is "Unknown user name or bad password" I then want to know if a login was sucessful. Can I set this up to show in the event viewer or some other easy way? Also can I set a threshold so that I will only see a sucessful logon if there are more than x number of bad login attempts?
0
Comment
Question by:LostInWindows
  • 2
4 Comments
 
LVL 18

Accepted Solution

by:
Don S. earned 175 total points
Comment Utility
Yes and no.  You can change the audit policy to include successful login attempts.  However, you can not descriminate which successful attempts are included.  It's either ALL successful or NO successful (which is the default).  If you want to filter the logs better than Windows does natively, you would need to get a 3rd party log viewing program - of which there are many.
0
 
LVL 1

Author Comment

by:LostInWindows
Comment Utility
Can you please provide the names of some 3rd Party log programs that are worthwhile?
Thanks
0
 
LVL 8

Assisted Solution

by:jako
jako earned 75 total points
Comment Utility
we, for instance use SawMill (http://www.sawmill.net/) which I can heartily recommend.

You can, of course, with a little PowerShell and ActivePERL magic accomplish all the required functionality with no need to shell out the dough ;)
0
 
LVL 1

Author Closing Comment

by:LostInWindows
Comment Utility
Thanks for the help!
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now