- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Logging events from a w2k12 DC?
Running into an issue, we have a DC that we want system logs etc pulled into SA. The issue of course is Domain Controllers do not contain local user/groups. Is there an easy work around without major administrative work to get this functioning on a DC we want logs from? I would like to hear what others have done in similar scenarios. Thanks!
- Tags:
- Community Thread
- Discussion
- Forum Thread
- Logs
- NetWitness
- NW
- NWP
- RSA NetWitness
- RSA NetWitness Platform
- windows_2012
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Someone must have come across this type of issue while implementing this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Collecting events from a Domain Controller is very common.
Have you reviewed the configuration steps here? http://sadocs.emc.com/@api/deki/files/43167/MicrosoftWindowsEventing.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I've reviewed the document, it's expected that the service account be added to the local Log Readers group. As you know, this can't be done on DC's since local users and groups do not exist. Hence the only way I can think of doing this is using the domain log readers group and having the potential risks of additional access.
