I imagine it’ll depend on the size of the organization. We have around 900 users in our domain. I’ve got the max log size on our DCs set to 2GB, and that captures about 9 days of entries.
That said, I don’t have a confident recommendation. I really don’t know what’s standard practice. I just wanted to have them retain a little better than a week in case we needed to go back a bit, and without having to pore through VM backups to get the info.
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Wednesday, January 3, 2024 3:02 PM
To: NTSysAdmin <ntsys...@googlegroups.com>
Subject: [ntsysadmin] Domain Controller Security Event Log settings in GPO
|
This message is from an external sender. |
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Biza4RgsLRFtBffAC17tBsZgLEE3_N-Ht34jSwVdo4QLw%40mail.gmail.com.
|
[CAUTION] Do not click on links or open attachments unless you recognize the sender and know the content is safe. |
I should have added that I use the stronger among the MS recommendations for auditing. What auditing policy you use will also affect size and time period captured. Audit Policy Recommendations | Microsoft Learn
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
Looking at Security event logs in situ is horrible and can have a major impact on DC performance. I’d strongly recommend using some tool to search them OFF the DCs.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Wright, John M
Sent: Wednesday, January 3, 2024 3:22 PM
To: ntsys...@googlegroups.com
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/DM6PR12MB4372BAE92DB225D86FE8C5629160A%40DM6PR12MB4372.namprd12.prod.outlook.com.
Looking at Security event logs in situ is horrible and can have a major impact on DC performance. I’d strongly recommend using some tool to search them OFF the DCs.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/f81f89c086364a16a4d360a1ad25eeaf%40smithcons.com.
Don’t make it hard.
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*</Select>
<Select Path="Security">*</Select>
<Select Path="System">*</Select>
</Query>
</QueryList>
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Bh82g4Vr7dxR-5rLnA1a7r5JC2_W9k8Yz9MKrm2mGb4XQ%40mail.gmail.com.
Don’t make it hard.
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*</Select>
<Select Path="Security">*</Select>
<Select Path="System">*</Select>
</Query>
</QueryList>
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/0512eab4ba224bd6a9f13630eced692c%40smithcons.com.
Keep in mind that you can scavenge any previous log sets from backup.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Skype: MPECSInc.
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/DM6PR12MB4372BAE92DB225D86FE8C5629160A%40DM6PR12MB4372.namprd12.prod.outlook.com.
Keep in mind that you can scavenge any previous log sets from backup.
Philip Elder MCTS
I didn’t see it called out specifically, so just checking, have you validated your DCs’ Security logs are actually configured to be 200MB on the DCs themselves? If so, you can probably adjust the existing GPO, then confirm the DCs update. FWIW, there are instances where particular policies are configurable in multiple areas of Group Policy, sometimes due to legacy/granular changes, but the client will apply the correct/relevant configuration, regardless. This may be one of those situations.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Bi_CpFTx%2BgO81zdQWphpr%2BVxn%3DHPXw9ZHU3L%3DHE8fqa0Q%40mail.gmail.com.
This is a pain as far as the overlap between “new” and “old” areas for what is essentially the same settings. The Windows Firewall has a lot of these issues.
So, here’s the thing, if the current “old” area settings are functioning as expected then tweak those. Don’t remove them after setting up the “new” area settings. That’s probably going to lead to grief with no way out but a restore.
So, update the current settings.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Skype: MPECSInc.
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Bi_CpFTx%2BgO81zdQWphpr%2BVxn%3DHPXw9ZHU3L%3DHE8fqa0Q%40mail.gmail.com.
Does it really matter which setting you use if you get the desired result? I’m not aware of a depreciation or recommendation against using either setting.
Do you have a test system, any Win version would do, that you can point the GPO settings at to see if they work like you want them to? Heck, set them to different values and let us know which one wins.
-Matt
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Thursday, January 4, 2024 8:27 AM
To: ntsys...@googlegroups.com
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Bi_CpFTx%2BgO81zdQWphpr%2BVxn%3DHPXw9ZHU3L%3DHE8fqa0Q%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/DM4PR14MB5718A54FAF7F9EBCBFEE1BB9FF672%40DM4PR14MB5718.namprd14.prod.outlook.com.
Don’t make it hard.
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*</Select>
<Select Path="Security">*</Select>
<Select Path="System">*</Select>
</Query>
</QueryList>
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/0512eab4ba224bd6a9f13630eced692c%40smithcons.com.