Solved

XP workstation display "Security log is full"  and I cannot login unless I am a local admin

Posted on 2013-01-03
6
647 Views
Last Modified: 2013-01-10
We have several XP workstations on our Windows 2008r2 domain. Recently several users have come to me and told me that they cannot log in. I go to their workstation and see a message similar to "security log is full" and something about how they need to be a local admin. I log in and make them local administrators and they are able to log in but when I go to clear the security log, it tells me I do not have the permissions and I am a Domain Admin, I also log in as the Administrator on the local workstation and try to clear the security log and I do not even permission as the local admin either. Has anyone seen this before? I know another IT person has been working with GPOs. Is it possible this is causing this? All advice welcome
0
Comment
Question by:Thor2923
6 Comments
 
LVL 23

Expert Comment

by:Thomas Grassi
ID: 38740064
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 38740067
What it sounds like is GPOs are being applied that is causing this problem

Computer Configuration\Administrative Templates\Windows Components\Event Log Service

http://technet.microsoft.com/en-us/library/cc778402(v=ws.10).aspx
0
 
LVL 24

Expert Comment

by:Mohammed Hamada
ID: 38740080
There must be something in the event log on those workstations event viewer related to security. could you please check and post them ?
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 10

Expert Comment

by:Pramod Ubhe
ID: 38740087
Yes that GPO should have some wrong settings. Edit that GPO to overwrite event logs and you can set the max space allocated to event logs.
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38740331
Login as the Administrator Click --> start --> Run --> type rsop.msc.

From the rsop menu , expand to Computer configuration --> Windows settings --> Security settings --> Event log --> Check which policy is applied.And make the changes as expalined above.
0
 
LVL 23

Expert Comment

by:Thomas Grassi
ID: 38740367
Get the IT person who updated the GPo to remove the settings

Sounds like they need to be reviewed

Locking down the event logs causing the users not be able to logon  well time to unlock the event logs.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question