This section describes how to configure the logging and auditing policy on various versions of Microsoft Windows. The syslog-ng agent can transfer log messages only about those events that are actually logged, so the audit policy has to be configured to log the important events.
Microsoft Windows operating systems can record a range of event types, from a system-wide event such as a user logging on, to an attempt by a particular user to read a specific file. Both successful and unsuccessful attempts to perform an action can be recorded. The audit policy specifies the types of events to be audited. When such an event occurs, an entry is added to the computer's log files.
Following is a brief overview on how to configure the audit policy on various versions of Microsoft Windows. For details, consult the documentation of your operating system, or visit Microsoft TechNet at http://technet.microsoft.com/. For details on configuring the auditing and logging of various applications, like the IIS Server or the ISA Server, consult your product documentation.
The following procedure describes how to enable security logging on Windows XP Professional and Windows 2000 hosts.
Procedure 5.4. Turning on security logging on Windows XP and Windows 2000
Login as an administrator.
Click , click , and type .
On the menu, click , and click .
Under , click , and click .
In , select , then click , click , and click .
In , select , then click .
Right-click the attribute or event you want to audit on the details pane.
Set the desired options in the .
Repeat Steps 7-8 for every other event you want to audit.
![]() |
Note |
|---|---|
To remotely enable security logging for workstations, member servers, and domain controllers, see Section 5.7.2, “Turning on security logging for domain controllers”. |
The following procedure describes how to enable security logging on a Windows XP Professional domain controller.
Procedure 5.5. Turning on security logging for domain controllers
Login as an administrator.
Click , point to , point to , and click .
In the console tree, click .
Click , then click .
On the tab, select the policy you want to change, and click .
In the window, in the console tree, click .
Right-click the attribute or event you want to audit on the details pane.
Set the desired options in the .
Repeat Steps 7-8 for every other event you want to audit.
The following procedure describes how to configure auditing on a Windows 2003 Server host.
Procedure 5.6. Turning on auditing on Windows 2003 Server
Login as an administrator.
Click , point to , point to , and click .
In the console tree, click , then .
Double-click on an event and select the Define these policy settings option.
Select the type of event to log: Success or Failure.
Repeat Steps 4-5 for every other event you want to audit.
© 2007 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com