Solved

Recreate Security Event Log in Windows Server 2008

Posted on 2010-08-17
9
1,113 Views
Last Modified: 2012-05-10
I could not access the Security event log on our domain controller with the domain administrator account. I tried a bunch of fixes and verified settings but still did not work. One suggestion was stopping the event log service, deleting the log (since I couldn't clear it either), and then restarting the service. I did this but the event log won't recreate. Turns out it's not in the recycle bin either. I've restarted as well, but no luck.

Any ideas? Administrators have access to the logs and it works fine for application and system logs. And it works fine on domain members, just not the single DC (need another one, I know).

Thanks!
0
Comment
Question by:MrSampsonite
  • 6
  • 2
9 Comments
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33463447
Check the permissions on C:\Windows\System32\winevt\Logs\Security.evtx
0
 

Author Comment

by:MrSampsonite
ID: 33464225
I checked. Administrators have full rights. As does System. And Event Log.

The Application and System.evtx files have LOCAL SERVICE as the owner. I had changed security to Administrators to see if it fixed it, but it didn't. So I'm changing it back now. Oh, btw, the file reappeared after a couple of reboots.

Anyway, any other ideas?
0
 
LVL 3

Expert Comment

by:TechGoddess82
ID: 33472332
Hi,

Have you checked the GPO's for any security permissions?

If not here are a few setting you may want to look at.

How to set event log security locally or by using Group Policy in Windows Server 2003
http://support.microsoft.com/kb/323076/

Regards,
TG82
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 

Author Comment

by:MrSampsonite
ID: 33474828
I checked and the CustomSD is not there for Security key. Should it be and for what values?

Those instructions are for Application and System logs. Is it safe/normal to do this for security log?


0
 

Author Comment

by:MrSampsonite
ID: 33484958
I also disabled all my custom GPOs, reset the settings, rebooted, verified they got the default gpos which have not been changed, and still the same thing. no access. access is denied (5).


0
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33486760
Use the below script... it will backup and clear the logs


strComputer = "."

Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate,(Backup, Security)}!\\" & strComputer & "\root\cimv2")
Set colLogFiles = objWMIService.ExecQuery ("SELECT * FROM Win32_NTEventLogFile Where LogfileName = 'System' OR LogFileName= 'Application'")

For Each objLogfile in colLogFiles
 errBackupLog = objLogFile.BackupEventLog("C:\Windows\System32\Winevt\Logs\"&objLogFile.LogfileName&"_BACKUP.evtx")
 If errBackupLog <> 0 Then
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - failed."
 Else
 objLogFile.ClearEventLog()
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - success."
 End If
Next
0
 

Author Comment

by:MrSampsonite
ID: 33486897
I don't get it. The log size is 0K. And I can't clear the logs through command line.


0
 

Author Comment

by:MrSampsonite
ID: 33486976
I ran the script. Ran successfully against the application and system log. It won't run again unless there's an entry in the log, which is fine. However if I change it to be the Security log, it fails. It's because there are no entries or because no access or both.
0
 

Accepted Solution

by:
MrSampsonite earned 0 total points
ID: 33650462
Nice try everyone. Going to close this. No solution worked. Format reinstall unfortunately.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question