?
Solved

User cannot logon on their computers because security log is full

Posted on 2011-09-23
10
Medium Priority
?
1,050 Views
Last Modified: 2012-05-12
Hi Experts,

Today I faced a weird problem with a client's active directory network. Because of a problem with replication, all sysvol content was deleted. After that all policies stopped to be applied at the computers. This was expected. Unexpected was the fact that no one could log in in their computers because of the following error:

The security log on this system is full

The error appears as a message box before user logon input. Users are not member of local admins, so they can't logon at all.

There is no GPO that enforces Logs configuration at the computers for retention or rotation at all. The only configuration we have in Domain is that Default Domain Policy sets some Audit Policies (sucess an failure for most events).

It's a fact that we are logging a lot of events at computers (much of them I know is useless. we will fix it soon). The Security Logs at the computers might be full or very close to its storage capacity. But we can't have it as the root cause of the problem since when domain policies were fixed, the error message gone away, users can login and security log keeps been filled up.

What is worse is that many users tried to logon this morning at the company's network with their laptops. As they couldn't logon, because of the security log error, they went back home and tried to work through vpn. Unfortunately when they started their laptops, the error message appeared again and didn't let them to log in to the computer.

These outside users came with a problem that we couldn't solve. They don't have local admins rights and we couldn't logon to their computers with our domain admins credentials because they were working from home. If someone asks "why dind't we give local admin's password to these users and instruct them to logon locally and fix the problem? Because we are not allowed to do that. All computers at the domain share the same local admin password. If we give it to one user, we have to change it all over the domain that span 3 different countries.

Anyone has any idea why this problem happened? In other words, If GPO fails to be applied at computer level, the security log issue doesn't let users to login on.

Thanks!

Rodrigo Garcone
0
Comment
Question by:garconer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
10 Comments
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 36591331
Use Group Policy to Set Your Application,security and System Log Security in default domain policy.Once this is set the user will not face login issue when the event log gets full on the worksation.

Location
Default Domain policy\Computer Configuration\Windows Settings\Security Settings\Event Log

Policy                                                          Setting
Maximum application log size                 10240 kilobytes
Maximum security log size                     10240 kilobytes
Maximum system log size                       10240 kilobytes
Retention method for application log           As needed
Retention method for security log               As needed
Retention method for system log                As needed




0
 

Author Comment

by:garconer
ID: 36592388
Sandes,

Tks for the reply but this is not the answer for the question. I know this settings you presented and it has been done. The issue is if gpo fail to be applied, even with the settings you suggested configured at gpo level, the security log error occurs
0
 
LVL 11

Expert Comment

by:Ackles
ID: 36592442
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 
LVL 11

Expert Comment

by:Ackles
ID: 36592450
0
 
LVL 11

Expert Comment

by:Ackles
ID: 36592453
Since you have problem with sysvol replication, you will have to do it on computers locally.
0
 

Author Comment

by:garconer
ID: 36592472
Hi Ackles,

Tks for the reply. The question is not related on how to configure Security Logs locally or using GPO. I know how to do that.

The question is why when gpo fails to be applied the log is full message appears and block users from log in to their computers.
0
 
LVL 11

Expert Comment

by:Ackles
ID: 36592480
Hi,
As you know that GPO get's applied at time scheduel which is either setup as default or specified via GP.
Now there are also Security GPO's which are applied even if there has nothing changed, I mean you are aware that only when there is a change in GPO they get applied, however Security GPO's are always applied even if there is no change. This might be the reason as Audit & other policies fail to apply & in turn fill up the logs.

Does that make sense?

A
0
 
LVL 11

Accepted Solution

by:
Ackles earned 2000 total points
ID: 36592489
0
 

Author Comment

by:garconer
ID: 36592495
Yes, it makes a lot of sense. That's answer the question. tks!
0
 
LVL 11

Expert Comment

by:Ackles
ID: 36592502
Glad that helped, Thanks for points!
A
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Here's a look at newsworthy articles and community happenings during the last month.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question