Solved

Recreate Security Event Log in Windows Server 2008

Posted on 2010-08-17
9
1,121 Views
Last Modified: 2012-05-10
I could not access the Security event log on our domain controller with the domain administrator account. I tried a bunch of fixes and verified settings but still did not work. One suggestion was stopping the event log service, deleting the log (since I couldn't clear it either), and then restarting the service. I did this but the event log won't recreate. Turns out it's not in the recycle bin either. I've restarted as well, but no luck.

Any ideas? Administrators have access to the logs and it works fine for application and system logs. And it works fine on domain members, just not the single DC (need another one, I know).

Thanks!
0
Comment
Question by:MrSampsonite
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 2
9 Comments
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33463447
Check the permissions on C:\Windows\System32\winevt\Logs\Security.evtx
0
 

Author Comment

by:MrSampsonite
ID: 33464225
I checked. Administrators have full rights. As does System. And Event Log.

The Application and System.evtx files have LOCAL SERVICE as the owner. I had changed security to Administrators to see if it fixed it, but it didn't. So I'm changing it back now. Oh, btw, the file reappeared after a couple of reboots.

Anyway, any other ideas?
0
 
LVL 3

Expert Comment

by:TechGoddess82
ID: 33472332
Hi,

Have you checked the GPO's for any security permissions?

If not here are a few setting you may want to look at.

How to set event log security locally or by using Group Policy in Windows Server 2003
http://support.microsoft.com/kb/323076/

Regards,
TG82
0
Raise the IQ of Your IT Alerts

From IT major incidents to manufacturing line slowdowns, every business process generates insights that need to reach the people required to take action. You need a platform that integrates with your business tools to create fully enabled DevOps toolchains.

You need xMatters.

 

Author Comment

by:MrSampsonite
ID: 33474828
I checked and the CustomSD is not there for Security key. Should it be and for what values?

Those instructions are for Application and System logs. Is it safe/normal to do this for security log?


0
 

Author Comment

by:MrSampsonite
ID: 33484958
I also disabled all my custom GPOs, reset the settings, rebooted, verified they got the default gpos which have not been changed, and still the same thing. no access. access is denied (5).


0
 
LVL 2

Expert Comment

by:zsaurabh
ID: 33486760
Use the below script... it will backup and clear the logs


strComputer = "."

Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate,(Backup, Security)}!\\" & strComputer & "\root\cimv2")
Set colLogFiles = objWMIService.ExecQuery ("SELECT * FROM Win32_NTEventLogFile Where LogfileName = 'System' OR LogFileName= 'Application'")

For Each objLogfile in colLogFiles
 errBackupLog = objLogFile.BackupEventLog("C:\Windows\System32\Winevt\Logs\"&objLogFile.LogfileName&"_BACKUP.evtx")
 If errBackupLog <> 0 Then
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - failed."
 Else
 objLogFile.ClearEventLog()
  Wscript.Echo "" &objLogFile.LogfileName& " event log backup and clear - success."
 End If
Next
0
 

Author Comment

by:MrSampsonite
ID: 33486897
I don't get it. The log size is 0K. And I can't clear the logs through command line.


0
 

Author Comment

by:MrSampsonite
ID: 33486976
I ran the script. Ran successfully against the application and system log. It won't run again unless there's an entry in the log, which is fine. However if I change it to be the Security log, it fails. It's because there are no entries or because no access or both.
0
 

Accepted Solution

by:
MrSampsonite earned 0 total points
ID: 33650462
Nice try everyone. Going to close this. No solution worked. Format reinstall unfortunately.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question