Displaying 2 results from an estimated 2 matches for "audit_success".
2006 May 30
1
Syslogging and remote installer (was RE: seg on windows-pr-0.5.1 (was RE: win32-eventlog 0.4.0))
...getting tricky. i''m getting empty records and weird characters too :)
>
> --------
> record_number : 20983290
> time_generated : Tue May 30 16:15:27 China Standard Time 2006
> time_written : Tue May 30 16:15:27 China Standard Time 2006
> event_id : 642
> event_type : audit_success
> category : 7
> description : User Account Changed:
> Target Account Name: ztest2
> Target Domain: DMPI
> Target Account ID: ?
> ??????21-1995071569-205336168-60295696-9240}
> Caller User Name: pe?aijm
> Caller Domain:...
2007 Dec 04
4
eventlog
...; all of them. the description is not complete or empty.
>
> in windows xp it works fine, eg
>
> #<struct Struct::EventLogStruct record_number=268, time_generated=Tue Dec 04 12:
> 10:48 +0800 2007, time_written=Tue Dec 04 12:10:48 +0800 2007, event_id=642, eve
> nt_type="audit_success", category=7, source="Security", computer="BG-MIS-PBOT",
> user="Pe\361aIJM", string_inserts=["-", "Guest", "BG-MIS-PBOT", "%{S-1-5-21-3438
> 18398-1177238915-839522115-501}", "Pe\361aIJM", "DMPI",...