|
Focus on Microsoft
Microsoft Audit Collection System Jul 19 2004 02:00PM Strand, John (John Strand mms gov) (1 replies) Re: Microsoft Audit Collection System Jul 19 2004 04:28PM Jean-Baptiste Marchand (Jean-Baptiste Marchand hsc fr) (1 replies) |
|
|
Privacy Statement |
There was a talk given on (M)ACS when I was at Tech*Ed 2004 in San
Diego at the end of May. The talk was very general in scope and didn't
specify a release date.
ACS seems like a very efficient (and secure) data collection engine
but, as another poster pointed out, it will rely entirely on the end
user to come up with a way to extract and analyze "interesting"
information from what could be a tremendous flow of entries into the
repository.
On a related note, if you're looking for something relatively simple
to look for logon successes/failures across machines, I have a perl
script that reads event logs from one or more Windows systems (including
NT) and summarizes authentication activity in various ways. It's free
for non-commercial use. See http://pantheon.yale.edu/~kjh27/logger.html
for more information.
- Ken Hoover
Jean-Baptiste Marchand wrote:
> Hello,
>
> * Strand, John <John.Strand (at) mms (dot) gov [email concealed]> [19/07/04 - 18:21]:
>
>
>>I was wondering if anyone has had experience with Microsoft Audit Collection
>>System. I understand that it has been in Beta for some time now, and it is
>>supposed to be a part of Server 2003 sp1.... maybe.
>>Just wanted to gather some more information from anyone who was/is on the
>>Beta team.
>
>
> I'm not sure if MACS is available or not.
>
> AFAIK, the only information about MACS was given by E. Fitzgerald in
> October 2003 in the loganalysis list :
>
> http://lists.jammed.com/loganalysis/2003/10/0024.html
>
> I've never heard about it since that time.
>
> Maybe you should ask on loganalysis@, E. Fitzgerald usually answers to
> questions directed to MS.
>
> Jean-Baptiste Marchand
--
Kenneth J. Hoover
Systems Programmer
Yale University ITS AM&T x2-1260
------------------------------------------------------------------------
---
------------------------------------------------------------------------
---
[ reply ]