Windows 2012 configuration for events collection
I. Add User
Ref :http://technet.microsoft.com/en-in/library/jj713507.aspx#BKMK_Manage1
II. Set log access policy
- Goto the "Administrative Tools"
- Select Local Security Policy
- Navigate to "Security Settings->LocaL Policies->User Rights Assignment
- On the right hand frame double click on the "Manage auditing and security log" option
- Add the user you created earlier.
Ref : http://technet.microsoft.com/en-us/library/cc957161.aspx
III. To grant DCOM remote launch and activation permissions for a user or group
- Click Start, click Run, type DCOMCNFG, and then click OK.
- In the Component Services dialog box, expand Component Services, expand Computers, and then right-click My Computer and click Properties.
- In the My Computer Properties dialog box, click the COM Security tab.
- Under Launch and Activation Permissions, click Edit Limits/Defaults.
- In the Launch Permission dialog box, follow these steps if your name or your group does not appear in the Groups or user names list:
- In the Launch Permission dialog box, click Add.
- In the Select Users, Computers, or Groups dialog box, add your name and the group in the Enter the object names to select box, and then click OK.
- In the Launch Permission dialog box, select your user and group in the Group or user names box. In the Allow column under Permissions for User, select Remote Launch and select Remote Activation, and then click OK.
- Under Launch and Access Permissions , click Edit Limits/Defaults.
- In the Access Permissions dialog box, follow these steps if your name or your group does not appear in the Groups or user names list:
- In the Access Permissions dialog box, click Add.
- In the Select Users, Computers, or Groups dialog box, add your name and the group in the Enter the object names to select box, and then click OK.
- In the Access Permissions dialog box, select your user and group in the Group or user names box. In the Allow column under Permissions for User, select Remote Access and then click OK.
- Clock OK on the COM Security tab
Ref http://technet.microsoft.com/en-us/library/bb633148.aspx
IV. Setting Namespace Security with the WMI Control
- click start, click Run, type wmimgmt.msc and press enter
- In the WMI Control pane, right-click WMI Control, choose Properties, and then select the Security tab.
- Expand the Root node, selet the CIMV2 entry and then press the Security button
- click on the advanced button. In the permission tab click on the Add button
- In the Select Users, Computers, or Groups dialog box, add your name and the group in the Enter the object names to select box, and then click OK.
- From the "Apply to" drop down select "This namespace and subnamespaces" option
- Under the Allow column, select "Enable Account" and "Remote Enable" options.
- Press the ok button on all open windows (until the WMI control panel exits)
Ref http://technet.microsoft.com/en-us/library/cc771551.aspx
V. Adding the user to “Event Log Readers” group
- Go to Start-Computer-(right-click)->Manage->tools(on right hand top corner)->Computer Management
- Local Users and Groups (on the left hand side tree)
- Double click on Users
- Select your user and do a right click
- Select properties from the menu
- Click on tab "Member of", on the new window
- Adding the user to the group "Event Log Readers",
- Click on Add... Button, type in "Event Log Readers" to search for the group.
- Click on Check Names... button, press Ok.
- Close all open windows.
Ref: http://technet.microsoft.com/en-us/library/cc748890.aspx
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*