Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED Event logging in Active directory

  • Thread starter Thread starter Sanjeev
  • Start date Start date
  • Replies Replies 2
  • Views Views 3K
Status
Not open for further replies.

Sanjeev

New Member
Messages
1
Reaction score
0
Points
1
Dear Experts,

i am having some issue with event logging.

here is my problem statement.

I need to survey how many users use pen drive in my organization.

I have created a GPO for object access through computer configuration>security policy>Advanced Audit policy configuration>system audit policies-local group policy>Object access.

When pen drives are plugged on the PC, it generate an event ID 4656, like wise i know pen drives was attempted in that PC.

but for central monitoring, and having >1000 pc, i cannot go on individual pc to check the security event log.

i have configured event subscription collector and enable all services needed. Events from windows 7 pc are successfully being forwarded to my collector.

so here are my issues:

1- i have to deploy winrm 2.0 on every XP pcs's as winrm is not installed by default. i cannot find the .msi version of winrm2.0. i do not want to deploy the .exe version using installation scripts.

2- PC having OS windows 8.1 are not forwarding any events to the collector. all the services are up (winrm quickconfig)

3- The above 2 are alternate solutions. WHAT I ACTUALLY WANT TO DO IS THAT INSTEAD OF THE LOG (EVENT ID 4656) BEING GENERATED ON THE LOCAL PC, I WANT THE LOG TO BE GENERATED ON THE DOMAIN CONTROLLER, JUST LIKE LOGON, LOGOFF EVENT ID'S)

4- Solution to issue no. 3 will be my no.1 priority, alternately, solution to no.2 and no.1 is highly welcomed.

Thanks.
 
What you have mentioned is correct. Allow the events to be logged in into the client machines and then let them forward to DC. I am not sure on why Win 8.1 PC's are not forwarding the events to the collector. Not sure why you are still using XP OS, why not upgrade to Win 7 ?.
 
Status
Not open for further replies.

Forum statistics

Threads
7,043
Messages
27,535
Members
17,729
Latest member
ironmonkey

Trending content

Back
Top