Enabling Auditing and Logging

Auditing and logging provide the ability to track user account activity, track logon and logoff date and time, see what files have been accessed, and determine what web pages have been viewed. Enabling auditing and logging allows you to track these events and provides the administrator with important security information, as follows:

  • Event logs— These logs are built into Windows NT4 Server, Windows 2000, and Windows XP and consist of the System Event Log, the Application Event Log, and the Security Event Log. The Event Viewer utility is used to view the logs and apply filters. The System Event Log tracks errors, warnings, and information about the operating system itself, its services, and the hardware it is running ...

Get CCIE Practical Studies: Security (CCIE Self-Study) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.