Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Recreate Security Event Log in Windows Server 2008

Posted on 2010-08-17
9
Medium Priority
?
1,134 Views
Last Modified: 2012-05-10
I could not access the Security event log on our domain controller with the domain administrator account. I tried a bunch of fixes and verified settings but still did not work. One suggestion was stopping the event log service, deleting the log (since I couldn't clear it either), and then restarting the service. I did this but the event log won't recreate. Turns out it's not in the recycle bin either. I've restarted as well, but no luck.

Any ideas? Administrators have access to the logs and it works fine for application and system logs. And it works fine on domain members, just not the single DC (need another one, I know).

Thanks!
0
Comment
Question by:MrSampsonite
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 2
9 Comments
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33463447
Check the permissions on C:\Windows\System32\winevt\Logs\Security.evtx
0
 

Author Comment

by:MrSampsonite
ID: 33464225
I checked. Administrators have full rights. As does System. And Event Log.

The Application and System.evtx files have LOCAL SERVICE as the owner. I had changed security to Administrators to see if it fixed it, but it didn't. So I'm changing it back now. Oh, btw, the file reappeared after a couple of reboots.

Anyway, any other ideas?
0
 
LVL 3

Expert Comment

by:TechGoddess82
ID: 33472332
Hi,

Have you checked the GPO's for any security permissions?

If not here are a few setting you may want to look at.

How to set event log security locally or by using Group Policy in Windows Server 2003
http://support.microsoft.com/kb/323076/

Regards,
TG82
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 

Author Comment

by:MrSampsonite
ID: 33474828
I checked and the CustomSD is not there for Security key. Should it be and for what values?

Those instructions are for Application and System logs. Is it safe/normal to do this for security log?


0
 

Author Comment

by:MrSampsonite
ID: 33484958
I also disabled all my custom GPOs, reset the settings, rebooted, verified they got the default gpos which have not been changed, and still the same thing. no access. access is denied (5).


0
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33486760
Use the below script... it will backup and clear the logs


strComputer = "."

Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate,(Backup, Security)}!\\" & strComputer & "\root\cimv2")
Set colLogFiles = objWMIService.ExecQuery ("SELECT * FROM Win32_NTEventLogFile Where LogfileName = 'System' OR LogFileName= 'Application'")

For Each objLogfile in colLogFiles
 errBackupLog = objLogFile.BackupEventLog("C:\Windows\System32\Winevt\Logs\"&objLogFile.LogfileName&"_BACKUP.evtx")
 If errBackupLog <> 0 Then
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - failed."
 Else
 objLogFile.ClearEventLog()
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - success."
 End If
Next
0
 

Author Comment

by:MrSampsonite
ID: 33486897
I don't get it. The log size is 0K. And I can't clear the logs through command line.


0
 

Author Comment

by:MrSampsonite
ID: 33486976
I ran the script. Ran successfully against the application and system log. It won't run again unless there's an entry in the log, which is fine. However if I change it to be the Security log, it fails. It's because there are no entries or because no access or both.
0
 

Accepted Solution

by:
MrSampsonite earned 0 total points
ID: 33650462
Nice try everyone. Going to close this. No solution worked. Format reinstall unfortunately.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question