Audit / Event 4609 / generate event when... Expand / Collapse
Author
Message
Posted 4/19/2014 5:29:39 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 4/19/2014 5:20:37 PM
Posts: 1, Visits: 0
Hi All.

I would like ask if can somebody advice me in my problem.

I need enable im system WIndows Server 2008 R2 event 4609 ( in SECURITY )which can inform me when server was reboot/shutdown.

I found article http://technet.microsoft.com/en-us/library/dd772631(v=WS.10).aspx and http://www.stigviewer.com/check/V-26553.
then enable this for testing in local policy and domain policy:

Policy:
Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit Security State Change" for success and failure

and

Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings" for enable

I tested this on Windows Server 2008 R2, Windows 8, Windows 7 and that dont work for me and audit only event 4608 which inform me about start system.... Can i ask aboue advice ? I had deadline for yesterday and i cant resolbe this problem....

After set this option i checked this this command
- "auditpol /get /category:*" and there is set Success and Failure
- gpresults /H file.html - and generate html output if domain policy are apply on system and policy are apply correct.

I know about events in SYSTEM event 12,13,41,1074,1076,6005,6006 thanks which i can tracking related activity ( with start and shutdown services and computer ) but this is not enought for me....

Unfortunatelly this settings not enable this event. Maybe something more shoud be enable too ? in policy ?


Additional information:

In below articles we dont see information about event 4609:
Windows 7 and Windows Server 2008 R2
http://support.microsoft.com/kb/977519

Windows Vista and in Windows Server 2008
http://support.microsoft.com/kb/947226

but

In below articles ( xls lists ) we can see information about event 4609:

Windows Server 2008 R2 and Windows 7
http://www.microsoft.com/en-us/download/details.aspx?id=21561

Windows Server 2008 and Windows Vista
http://www.microsoft.com/en-us/download/details.aspx?id=17871

Windows 7, Windows Server 2008 R2 - general description policy
http://technet.microsoft.com/en-us/library/dd772631 and
for Windows 7, Windows 8, Windows 8.1, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2
http://technet.microsoft.com/en-us/library/dn311493.aspx


What sources are true ? and how should work this ?


Please about help.

Sebastian
Post #1337
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 5:48pm