Monitor Security Eventlog on Server 2008
Home  » Forums  » Monitor Security Eventlog on Server 2008

Monitor Security Eventlog on Server 2008
Posted: Mon, Jan 04, 2010 4:13 AM :: Rank: 3
Author
Points: 150
Level: System Center Hero

I wanted to monitor whether the groupmemebership of Domain Admins changes. So I created a rule that checks Windows Security Eventlog for Event ID 5136 and Parameter 9 containing Domain Admins.

I disabled this rule and made an override to activate it for my Domain Controller Group (containing 3 Domain Controllers Windows Server 2008). These Domain Controllers are in an untrusted site, connected via a SCOM Gateway Server.
Soon after I made the override I get this error on the SCOM Console: Processing Packlogged Events Taking a Long Time.
“The Windows Event Log Provider monitoring the Security Event Log is 2782 minutes behind in processing
events. This can occur when the provider is restarted after being offline for some time, or there
are too many events to be handled by the workflow.”
I checked the Security Eventlog on the Domain Controller Server 2008, there are a lot! Too many mayby for SCOM?
-Anyone has experience with monitoring Security Eventlogs on Server 2008? (I haven’t had this problems with Server 2003)
-Maybe this is a problem because it’s a remote site with a Gateway?
 
Thank you very much for any inputs :-)
   Report Abuse
Re: Monitor Security Eventlog on Server 2008
Posted: Mon, Jan 04, 2010 10:27 AM :: Rank: 0
Author
Points: 30429
Level: System Center Expert

The Remote Gateway should not interfere with this Event Collection.I am in the middle of creating a MP for Windows 2K8 domains and also have found this is not as straight forward as Win2k3. What are you using (if anything) in the Event Source Field?

   Report Abuse
RE: Monitor Security Eventlog on Server 2008
Posted: Mon, Jan 04, 2010 10:08 AM :: Rank: 0
Author
Points: 150
Level: System Center Hero

Its an Alert Generating Rule: NT Event Log. Event Source Log Name is: Security.

Configuration is: Event ID Equal 5136 AND Parameter 9 Contains Domain Admins

Rule Target is Windows Domain Controller, but as mentioned the rule is disabled and overrided to enable for my 3 specific Domain Controllers only.

   Report Abuse
Re: Monitor Security Eventlog on Server 2008
Posted: Sun, Jan 10, 2010 4:59 PM :: Rank: 1
Author
Points: 30429
Level: System Center Expert
Hi Maria, have a look at this to see if it helps

http://www.systemcentercentral.com/BlogDetails/tabid/143/IndexID/58421/Default.aspx
   Report Abuse
Re: Monitor Security Eventlog on Server 2008
Posted: Tue, Jan 12, 2010 5:44 AM :: Rank: 0
Author
Points: 150
Level: System Center Hero
Hi Simon



Thanks a lot for your post. This makes sense. So I added the Event Source Expression "Microsoft-Windows-Security-Auditing" but i still get errors "Processing Backlogged Events". We are only 20 AD Users, but our 3 AD Server 2008 creates thousands of events every minute. Seems that SCOM can't handle these... ? :-/
   Report Abuse
Re: Monitor Security Eventlog on Server 2008
Posted: Wed, Jan 27, 2010 3:47 AM :: Rank: 0
Author
Points: 1372
Level: System Center Specialist
Have you had a look at R2 Cumulative Update 1 ( http://support.microsoft.com/kb/974144/en-us ). Among many other things it should fix the backlogged event processing. Read the installation instructions carefully, though. Applying the update requires several steps to be followed.
   Report Abuse

Home  » Forums  » Monitor Security Eventlog on Server 2008
Tag Cloud
Quick Links
Top Contributors
Featured Members
Pete Zerger
Points: 41211
Level: System Center Expert
Simon Skinner
Points: 30429
Level: System Center Expert
Tommy Gunn
Points: 29964
Level: System Center Expert
Stefan Koell
Points: 20109
Level: System Center Expert
Tenchuu
Points: 15261
Level: System Center Expert