Monday, November 29, 2010

Windows Auditing can be annoying. (Shut up already)

My audit logs were filling up with a bunch of B.S. from perfectly good packets being successfully sent and received. (event id 5157, and 5152) By default, Windows thinks you want all of these packets logged... and perhaps some admins do. But they can be logged in the firewall log, I don't want them in the event log too. (Default location of the Windows Firewall log is at "C:\Windows\system32\LogFiles\Firewall\pfirewall.log") So after a bunch of googleing, I found several answers that almost worked. Here is what really worked for me on Windows 2008 R2 and R1:


auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable

auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable

So there you go, save some audit log space for something that matters, like non-firewall stuff.
-Bryan

(oh, and one more thing, if you want to create a Group policy for this, it is under
computer configuration --> policies --> windows settings --> security settings --> advanced audit policy configuration --> audit policies --> object access. Then double click "Audit Filtering Platform Connection" and check only the box next to "configure the following audit events." DO NOT CLICK THE OTHER TWO BOXES. Repeat for "Audit Filtering Platform Packet Drop" too. If this does not work, edit your GPO to include the policy outlined in Method 1, steps 2 and 3 from http://support.microsoft.com/kb/921468 .  REMEMBER, THE GPO MIGHT TAKE SOME TIME, so if you don't reboot, give it at least 90 min before you give up on the GPO idea.)

9 comments:

  1. Hello all,

    Nice blog! Auditing can be especially helpful for tracking use of very sensitive files such as paycheck, credit card data, R and D records and proprietary options. Windows auditing is also valuable pertaining to tracking usage of expensive-to-operate methods such as a color beam of light printer or examine the printer. Thank you...

    Windows Auditing

    ReplyDelete
  2. To use Advanced Audit Policy Conf you must enable Audit: Force audit policy subcategory settings for Vista/later under Local Policies\Security Options must be enabled.

    http://support.microsoft.com/kb/921468

    ReplyDelete
  3. This setting can be very tricky if you have migrated from w2k3 to w2k8 domain, because if you have not set auditing policies through advanced audit policy configuration but are still using old audit GPO settings, and you just turn off Windows Filtering Platform auditing, you will actually turn auditing off completely. More about this at:
    http://blogs.technet.com/b/askds/archive/2011/03/11/getting-the-effective-audit-policy-in-windows-7-and-2008-r2.aspx

    ReplyDelete
  4. Prudent Chartered Accountants is a leading provider of accounting, auditing and management consultancy in the Dubai, UAE. We provide accountancy and auditing services through Middle East. Our professional and qualified team has a wealth of knowledge and experience in areas such as taxation, corporate finance, litigation support, audit assurance and accounting.

    ReplyDelete
  5. I've been looking for a way to do this (group policy) for some time now. THANKS!!!

    ReplyDelete
  6. Great Post! Thank you such a great amount for sharing. continue blogging...
    file server auditing

    ReplyDelete
  7. Let's tell the artiste deposits 1,000 baht and gets a 100% bonus, most of which casino hotel kochi are tall bonuses. Usually applied from the first member, return to our account and enlargement 1,000 Baht to acquire 100% bonus. If the online gambling website determines that the artiste must point of view 30 laps, this means that the gambler must bet 1,000 30 = 30,000 baht, which is not explained here. Players must bet to acquire 30,000 baht, but the direction will be the epoch of betting which will be bet at 50/50 captivation rate. No business the outcome or loss. This means that the artist has completed a turnover of 500 baht.

    ReplyDelete
  8. You can choose to bet in any room, any table, any time, and you can choose according to your ability.
    Enter the betting channel with the legendary popular card 918kiss ios download game Baccarat. Just pick up your premium phone or smartphone anytime, anywhere. Access to world-class entertainment venues from our online casinos.
    https://918register.weebly.com/

    ReplyDelete