Guest RedFoxy Posted March 25, 2008 Share Posted March 25, 2008 Hi all! I've actived the auditing of terminal services but i've a strange trouble... I found a lot of connections but i've an hole in the sequences of connections, i've connections from rdp-tcp#3 to rdp-tcp#17 and after rdp-tcp#19 but i've a snapshot where i see rdp-tcp#18 but it isn't logged in the event log, is it possible? I've enabled the audit just running "actve directory user and computer" then i right click on the domain tree and i selected propriety, after that i clicked on group plocy and then on open button, in that window i do "create and link a GPO here" and i call it Audit, then i edited it and i goes to Computer config -> Windows settings-> local protection -> local policy -> audit policy -> and i've enabled "audit account logon events", "Audit logon events", "audit account management", "Audit system events" But after i activated it i don't see new terminal server connections in the event log.... Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.