Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

2003 Domain Controller log offs.

Posted on 2014-09-25
6
Medium Priority
?
145 Views
Last Modified: 2014-09-30
In my Event Viewer for Security I have 40,000+ log offs (event ID 538) yet only 6 logons. Why the disparity?
0
Comment
Question by:xmouser
  • 3
  • 3
6 Comments
 
LVL 29

Expert Comment

by:Dan McFadden
ID: 40345534
Have you enabled auditing of privilege use?  An excessive number of 538 could be an indication of the policy being turned on.

I suggest checking out the configuration of the Security Auditing policy.  Using Group Policy Manager go to:

1. Computer Configuration > Windows Settings > Security > Local > Audit
2. verify what is enabled
3. if privilege use auditing is enabled, disabled it

You can also do this locally by using  the Local Security Policy admin tool.  Go to:

1. Local Policies > Audit Policy
2. verify what is enabled
3. disable auditing objects as desired.

Dan
0
 

Author Comment

by:xmouser
ID: 40345858
Not seeing where I can specifically turn this off - not sure I should. But why so many log offs 40,000+ in comparison to 6 logons for the same week?
0
 
LVL 29

Expert Comment

by:Dan McFadden
ID: 40346034
There could be many reasons.  What is installed on this server?

See thread for a description of a similar situation:  http://social.technet.microsoft.com/Forums/windowsserver/en-US/5b4ce879-ed35-432f-8d60-30cfbbc6b62f/2003-sp2-dc-filling-up-with-event-id-538-540-and-576?forum=winserversecurity

Dan
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:xmouser
ID: 40346143
2003 Domain Controller.
0
 
LVL 29

Accepted Solution

by:
Dan McFadden earned 2000 total points
ID: 40346166
Nothing else? No Exchange, SharePoint, etc...

If not, then you could disable the "Audit privilege use" policy on the DC.  This should reduce the 538s.

Unless you have some need to have had this option enabled, I suggest turning it off.

Reference link:  http://technet.microsoft.com/en-us/library/cc784501(v=ws.10).aspx

Dan
0
 

Author Comment

by:xmouser
ID: 40346296
I'll check.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question