Admin Tip #159: New system events in NT4 SP4

Hits: Failed to execute CGI : Win32 Error Code = 3


SP4 Event Log Service records new events in the system event log that are useful in measuring operating system availability.

Prior to SP4, the recording of operating system crashes in the event log (Save Dump events) was optional. By default, crash events were recorded but a system administrator could disable this behavior in the System control panel by clearing "Write an event to the system log when a STOP error occurs" on the Startup/Shutdown tab. In SP4, the recording of crashes in the event log is mandatory for Windows NT Server and can't be disabled by an administrator. There is no change for Windows NT Workstation; an administrator can still choose either setting.

Other Event IDs:

ID 512 : System Restart
ID 517 : Security Log Cleared
Only individuals with Manage Auditing and Security Log rights can clear the security log.
ID 612 : Audit Policy Change

Event Log Tips:

Archiving Event Logs
Event Log explained
How to Delete Corrupt Event Viewer Log Files
Forensics: CrashOnAuditFail
Restrict access to Application and System event logs
Security Event Descriptions
Security Events Logon Type Definitions
Security Log Location
Suppress Browser Event Log Messages
Suppress Prevent logging of print jobs
System events in NT4 SP4
User Authentication with Windows NT
User Rights, Definition and List

Frank Heyne has made available a Windows NT Eventlog FAQ .

Book Recommendation:



A must have for NT administrators in corporate or governmental organizations or anyone being audited by a large outside audit firm.
It is not a secrets type guide but it has excellent sound advice and its used by PriceWaterhouse's auditors as a guide.