Answered by:
What functional level to get combined audit events?

Question
-
Hi,
At what functional level do you see all audit events as generated by all DCs on one DC? I've read it recently but can't remember if it's 2003 R2 or 2008.
Thanks.
Rich.
- Moved by Boo_MonstersInc Thursday, July 5, 2012 1:37 AM (From:Management)
Wednesday, July 4, 2012 1:39 PM
Answers
-
Hi,
Unfortunately, I didn't understand your question. However, events can be store in a centralized database in Operations Manager 2007.
About Audit Collection Services (ACS) in Operations Manager 2007
http://technet.microsoft.com/en-us/library/bb381373.aspxCollecting Security Events Using Audit Collection Services in Operations Manager
http://technet.microsoft.com/en-us/library/hh212908.aspxBest Regards,
Abhijit Waikar.
MCSA 2003 | MCSA:Messaging | MCTS | MCITP:Server Administrator | Microsoft Community Contributor | My Blog
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- Proposed as answer by Sandesh Dubey Thursday, July 5, 2012 6:12 AM
- Marked as answer by Miya Yao Tuesday, July 17, 2012 7:14 AM
Thursday, July 5, 2012 6:02 AM -
In addition to above if your goal is to collect log at central location refer below links.
Quick and Dirty Large Scale Eventing for Windows
http://blogs.technet.com/b/wincat/archive/2008/08/11/quick-and-dirty-large-scale-eventing-for-windows.aspxHow to collect security logs using event forwarding?
http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/8434ffb3-1621-4bc5-8311-66d88b215886Set up event subscriptions in Windows 2008
http://www.itexpertmag.com/server/set-up-event-subscriptions-in-windows-2008Windows Server 2008 Event Subscription with Task Scheduling
http://technet.microsoft.com/en-us/edge/Video/ff944915Event Subscriptions
http://technet.microsoft.com/en-us/library/cc749183.aspxConfigure Computers to Forward and Collect Events
http://technet.microsoft.com/en-us/library/cc748890.aspx
Reference link:http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/f82d4872-601f-47c0-8c84-e2cac269fe00/
Hope this helps
Best Regards,
Sandesh Dubey.
MCSE|MCSA:Messaging|MCTS|MCITP:Enterprise Adminitrator | My Blog
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- Marked as answer by Miya Yao Tuesday, July 17, 2012 7:14 AM
Thursday, July 5, 2012 6:15 AM
All replies
-
Hi,
Unfortunately, I didn't understand your question. However, events can be store in a centralized database in Operations Manager 2007.
About Audit Collection Services (ACS) in Operations Manager 2007
http://technet.microsoft.com/en-us/library/bb381373.aspxCollecting Security Events Using Audit Collection Services in Operations Manager
http://technet.microsoft.com/en-us/library/hh212908.aspxBest Regards,
Abhijit Waikar.
MCSA 2003 | MCSA:Messaging | MCTS | MCITP:Server Administrator | Microsoft Community Contributor | My Blog
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- Proposed as answer by Sandesh Dubey Thursday, July 5, 2012 6:12 AM
- Marked as answer by Miya Yao Tuesday, July 17, 2012 7:14 AM
Thursday, July 5, 2012 6:02 AM -
In addition to above if your goal is to collect log at central location refer below links.
Quick and Dirty Large Scale Eventing for Windows
http://blogs.technet.com/b/wincat/archive/2008/08/11/quick-and-dirty-large-scale-eventing-for-windows.aspxHow to collect security logs using event forwarding?
http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/8434ffb3-1621-4bc5-8311-66d88b215886Set up event subscriptions in Windows 2008
http://www.itexpertmag.com/server/set-up-event-subscriptions-in-windows-2008Windows Server 2008 Event Subscription with Task Scheduling
http://technet.microsoft.com/en-us/edge/Video/ff944915Event Subscriptions
http://technet.microsoft.com/en-us/library/cc749183.aspxConfigure Computers to Forward and Collect Events
http://technet.microsoft.com/en-us/library/cc748890.aspx
Reference link:http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/f82d4872-601f-47c0-8c84-e2cac269fe00/
Hope this helps
Best Regards,
Sandesh Dubey.
MCSE|MCSA:Messaging|MCTS|MCITP:Enterprise Adminitrator | My Blog
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- Marked as answer by Miya Yao Tuesday, July 17, 2012 7:14 AM
Thursday, July 5, 2012 6:15 AM -
Hello,
functional levels do not apply for event logs.
If you like to collect all events on one DC you have to configure it yourself with Event subscriptions, see the already posted links how to configure it.
Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Thursday, July 5, 2012 6:27 AM -
There is no way to generate event of all the DC into the one DC. Each DC maintains its own event log for authentication or changes in the AD objects, instead you can capture the log using third party tools like Snare or from quest. Event subscription services are available from windows 2008 & above to configure & forward critical events to the particular mail using SMTP address.
http://sourceforge.net/projects/snare/
Awinish Vishwakarma - MVP - Directory Services
My Blog: awinish.wordpress.com Disclaimer This posting is provided AS-IS with no warranties/guarantees and confers no rights.Thursday, July 5, 2012 1:14 PM