Windows event logs to filter/ignore
"Youngquist, Jason R." <[email protected]> Wed, 22 Sep 2010 09:54:17 -0500
| Newsgroups | gmane.comp.security.microsoft |
|---|---|
| Message-ID | <[email protected]> |
We are sending logs from Windows servers to a centralized collector. The W= indows servers are consistently sending all kinds of events to the collecto= r. I'm seeing a bunch of Security:538 and Security:576 events. For exampl= e, one particular server is sending Security:538 events and Security:576 ev= ents several times a minute. Over a period of time that I was looking at, = these two events accounted for 92% of the events being sent from the server= . When I looked at the events they basically said the same thing over and = over...Security:576 - "Special privileges assigned to new login, username: = administrator...." And Security:538 - "User Logoff: User name: administra= tor...." I'd like to filter out these events before they hit the collector, but I'm = afraid of filtering out too much and potentially missing a log entry that c= ould help with an incident, while at the same time I don't want to send and= store logs that aren't useful. Thoughts?=20 Thanks.=20 Jason Youngquist