Auditing Terminal service: strange trouble

R

RedFoxy

Guest
Hi all!

I've actived the auditing of terminal services but i've a strange trouble...

I found a lot of connections but i've an hole in the sequences of

connections, i've connections from rdp-tcp#3 to rdp-tcp#17 and after

rdp-tcp#19 but i've a snapshot where i see rdp-tcp#18 but it isn't

logged in the event log, is it possible?

I've enabled the audit just running "actve directory user and computer"

then i right click on the domain tree and i selected propriety, after

that i clicked on group plocy and then on open button, in that window i

do "create and link a GPO here" and i call it Audit, then i edited it

and i goes to Computer config -> Windows settings-> local protection ->

local policy -> audit policy -> and i've enabled "audit account logon

events", "Audit logon events", "audit account management", "Audit system

events"

But after i activated it i don't see new terminal server connections in

the event log....

 
Top Bottom