How to define access to just the System event log on Windows 2008 Server

0

I want to restrict administrator user access to the Security event log, is there a way to do it? I was following this article, but so far no luck.

user2644318

Posted 2014-02-25T20:21:26.480

Reputation: 101

What do you mean by "logging any security event" exactly? You don't want their actions to show in the Security Event Log? – Ƭᴇcʜιᴇ007 – 2014-02-25T20:28:31.413

Sorry, what I meant was I don't want the current user to receive any security event logs in the Event Viewer. – user2644318 – 2014-02-25T20:37:40.023

1"I don't want the current user to receive any security event logs" - Still not sure what you mean. How are they "receiving" security events currently? – Ƭᴇcʜιᴇ007 – 2014-02-25T20:39:10.037

I mean how do I define access to just the System event log on Windows 2012 Server. – user2644318 – 2014-02-25T20:51:29.080

Ok, so you want a user to be able to access the System event log, but not the Security event log? – Ƭᴇcʜιᴇ007 – 2014-02-25T20:53:38.783

Yes, exactly. Sorry for the bad description. – user2644318 – 2014-02-25T20:55:31.120

1Ok, can you do us all a favor (including yourself) and Edit your question to reflect what it is you are actually looking for? As-is it doesn't make much sense. Also include if the user is an administrator or not. – Ƭᴇcʜιᴇ007 – 2014-02-25T20:58:15.463

From MS: Event Logging Security

– Ƭᴇcʜιᴇ007 – 2014-02-25T20:59:38.873

I think I can do it using SDDL.

– user2644318 – 2014-02-25T21:26:43.880

Ok cool you edited it, now note: Standard non-admin users can't view the Security log by default. So I'm not sure why you're trying to accomplish this, as they shouldn't be able to get at it in the first place. – Ƭᴇcʜιᴇ007 – 2014-02-25T21:32:11.773

Sorry, I mean restrict administrators access to view Security Log. – user2644318 – 2014-02-27T15:16:18.247

No then. You can't restrict an administrator from anything, as they can just give themselves needed permissions. – Ƭᴇcʜιᴇ007 – 2014-02-27T15:27:40.767

Answers

0

You could try by removing the users' SE_SECURITY_NAME privilege (some info on how), which is the privledge that allows reading and clearing the Security Event Log.

But in reality, you can't restrict an administrator user from anything, as they can just give themselves needed permissions to access it.

Ƭᴇcʜιᴇ007

Posted 2014-02-25T20:21:26.480

Reputation: 103 763