Distinguishing Windows NT Audit Event Records (140714)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional
- Microsoft Windows NT Workstation 3.5
- Microsoft Windows NT Workstation 3.51
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows NT Server 3.5
- Microsoft Windows NT Server 3.51
- Microsoft Windows NT Server 4.0
This article was previously published under Q140714 SUMMARY
Auditing log on and log off events on Windows NT Workstation or Server
versions 3.5 and 3.51 produces records in the Security Log. However, what
appear to be identical records in the Security Log may actually record
network log on and log off events, interactive log on and log off events,
initial network connections to a share, or disconnects from the share.
Although these events may be identical at the summary level in the Security
Log, the details screen makes some distinctions among them.
Modification Type: | Major | Last Reviewed: | 5/7/2003 |
---|
Keywords: | kbinfo kbusage KB140714 |
---|
|