Re: Windows event logs to filter/ignore
[email protected] 22 Sep 2010 15:21:10 -0000
| Newsgroups | gmane.comp.security.microsoft |
|---|---|
| Message-ID | <[email protected]> |
Hi, you may consider to change your policy to no longer audit the success= of privilege use. See http://support.microsoft.com/kb/264769 .=0D 576 event log exercise of rights, being nice to have to track some Admini= strative logons. The event is the same no matter the object is (user or c= omputer accounts).=0D You may keep your policy and :=0D - filter out the event 576 when the user last caracter is $ (SeSecurityPr= ivilege)=0D - filter out Computer's event related: filter the event 576 when the user= is SYSTEM. (all others Se....Privilege)=0D christophe