Solved

XP workstation display "Security log is full"  and I cannot login unless I am a local admin

Posted on 2013-01-03
6
641 Views
Last Modified: 2013-01-10
We have several XP workstations on our Windows 2008r2 domain. Recently several users have come to me and told me that they cannot log in. I go to their workstation and see a message similar to "security log is full" and something about how they need to be a local admin. I log in and make them local administrators and they are able to log in but when I go to clear the security log, it tells me I do not have the permissions and I am a Domain Admin, I also log in as the Administrator on the local workstation and try to clear the security log and I do not even permission as the local admin either. Has anyone seen this before? I know another IT person has been working with GPOs. Is it possible this is causing this? All advice welcome
0
Comment
Question by:Thor2923
6 Comments
 
LVL 23

Expert Comment

by:Thomas Grassi
ID: 38740064
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 38740067
What it sounds like is GPOs are being applied that is causing this problem

Computer Configuration\Administrative Templates\Windows Components\Event Log Service

http://technet.microsoft.com/en-us/library/cc778402(v=ws.10).aspx
0
 
LVL 23

Expert Comment

by:Mohammed Hamada
ID: 38740080
There must be something in the event log on those workstations event viewer related to security. could you please check and post them ?
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 10

Expert Comment

by:Pramod Ubhe
ID: 38740087
Yes that GPO should have some wrong settings. Edit that GPO to overwrite event logs and you can set the max space allocated to event logs.
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38740331
Login as the Administrator Click --> start --> Run --> type rsop.msc.

From the rsop menu , expand to Computer configuration --> Windows settings --> Security settings --> Event log --> Check which policy is applied.And make the changes as expalined above.
0
 
LVL 23

Expert Comment

by:Thomas Grassi
ID: 38740367
Get the IT person who updated the GPo to remove the settings

Sounds like they need to be reviewed

Locking down the event logs causing the users not be able to logon  well time to unlock the event logs.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
This article runs through the process of deploying a single EXE application selectively to a group of user.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question