Windows event logs to filter/ignore

"Youngquist, Jason R." <[email protected]> Wed, 22 Sep 2010 09:54:17 -0500
Newsgroups gmane.comp.security.microsoft
Message-ID <[email protected]>
We are sending logs from Windows servers to a centralized collector.  The W=
indows servers are consistently sending all kinds of events to the collecto=
r.  I'm seeing a bunch of Security:538 and Security:576 events.  For exampl=
e, one particular server is sending Security:538 events and Security:576 ev=
ents several times a minute.  Over a period of time that I was looking at, =
these two events accounted for 92% of the events being sent from the server=
.  When I looked at the events they basically said the same thing over and =
over...Security:576 - "Special privileges assigned to new login, username: =
administrator...."  And Security:538 - "User Logoff:  User name: administra=
tor...."

I'd like to filter out these events before they hit the collector, but I'm =
afraid of filtering out too much and potentially missing a log entry that c=
ould help with an incident, while at the same time I don't want to send and=
 store logs that aren't useful.

Thoughts?=20


Thanks.=20
Jason Youngquist