When you enable success and failure Audit Privilege Usage auditing, and save a system information file when logged on as an administrator, the following event is logged:
Event Type: Failure Audit Event Source: Security Event Category: Privilege Use Event ID: 578 Date: 12/3/2002 Time: 3:23:33 PM User: Name \Administrator Computer: Name Description: Privileged object operation: Object Server: Eventlog Object Handle: 0 Process ID: 264 Primary User Name: Name Primary Domain: Name Primary Logon ID: (0x0,0x3E7) Client User Name: Administrator Client Domain: Name Client Logon ID: (0x0,0x9792) Privileges: SeSecurityPrivilegeThis is expected behavior when using the SeSecurityPriviledge privilege.
0 comments
Hide comments