fortypoundhead.com

Restricting Access to the Event Logs

Posted On 2007-05-03 by FortyPoundHead
Keywords: Restricting Access to the Event Logs
Tags:  Windows NT Windows 2000
Views: 1531


The Windows NT event log contains records documenting application, security and system events taking place on the machine. These logs can contain sensitive data, and by default, the Guest account has access to view them. This tweak allows you to restrict access to administrators and system accounts only.
Open your registry and find the key below.
Under this key are three sub-keys: Application, Security and System. These subkeys represent each section of the event log. To restrict access to each section create a new DWORD value of 'RestrictGuestAccess' under each sub-key and set it to equal '1'. To restrict access to only certain sections, then only add the value to that specific key.
Restart the machine for changes to take affect.

Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog]
Value Name: RestrictGuestAccess
Data Type: REG_DWORD
Data: (0 = Guest Access, 1 = Restricted Access)


About the Author

FortyPoundHead has posted a total of 1974 articles.

 


Comments On This Post

No comments on this post yet!


Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:54.166.189.88

Before you can post, you need to prove you are human. If you log in, this test goes away.



Recent Forum Posts

SSL Now Active
dwirch posted on June 16, 2017 at about 8:40 in Site News

SSL Now Active
dwirch posted on June 13, 2017 at about 7:59 in Site News

Coding Archive?
dwirch posted on June 3, 2017 at about 12:54 in Site News

Job Spammer: Bharti Jigyasi
dwirch posted on June 2, 2017 at about 16:57 in Spammers

Coding Archive?
dwirch posted on May 25, 2017 at about 12:38 in Site News

BWASL returns
dwirch posted on May 13, 2017 at about 15:24 in Site News