Re: Windows event logs to filter/ignore

[email protected] 22 Sep 2010 15:21:10 -0000
Newsgroups gmane.comp.security.microsoft
Message-ID <[email protected]>
Hi, you may consider to change your policy to no longer audit the success=
 of privilege use. See http://support.microsoft.com/kb/264769 .=0D
576 event log exercise of rights, being nice to have to track some Admini=
strative logons. The event is the same no matter the object is (user or c=
omputer accounts).=0D
You may keep your policy and :=0D
- filter out the event 576 when the user last caracter is $ (SeSecurityPr=
ivilege)=0D
- filter out Computer's event related: filter the event 576 when the user=
 is SYSTEM. (all others Se....Privilege)=0D
christophe