Reading Security Logs Windows Server 2012...


bit elementary questions here, appreciated. attempting determine time when specific computer logged onto our domain... more specifically, if computer logged onto our domain within specified time range, , if so, applications opened during time frame. viewing security logs computer. when @ list, under "source" column, there line item called "eventlog". double click , opens window stating, "the event logging service has shut down". mean cannot access information need? if so, how turn event log service on?

hi,

it seems recieve event id 1100 — runtime:

http://technet.microsoft.com/en-us/library/dd315576(v=ws.10).aspx

this normal condition. no further action required.

on dc, under security log, when users logon domain, see event log. applications used, not achieved dc.

i suggest log on 1 test computer, , open 1 application, , check event viewer logs indicate application opened. far know, applications openning could not be logged in event viewer.

regards,

yan li


we trying better understand customer views on social support experience, participation in interview project appreciated if have time.
helping make community forums great place.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS