[OpsMgr] ACS: How to enable auditing in Geneva Server Beta
July 22nd, 2009
Before OpsMgr ACS is able to collect token related audit events (Event ID 299), auditing needs to be enabled on each Geneva Server on the farm. This will create a lot of audits, which you may need to filer using Noise Filtering on your assigned Audit Collector Server, I will cover how we achieved noise filtering on our platform on other post, for now, I want to share a couple of easy steps to centrally enable audits on your Geneve Servers,
1) In Geneva Server MMC for each Geneva Server on the farm
- Root node
- Edit Service Properties
- Check “Success” and “Failure” Events
2) In Active Directory
- Create a GPO and link to the Geneva Servers OU
- Enable Audits
- Navigate to Security Settings->Local Policies->Audit Policy.
- Click on the “Audit object access” Security Setting on the list view at the right side pane.
- On the “Local Security Setting” tab, click the “[ ] Success” and/or “[ ] Failure” check boxes according to your needs.
- Give Permissions to the account
- Click Security Settings -> Local Policies -> User Rights Assignment.
- Double click “Generate Security Audits” and add the account of your service to Local Security Settings (you can verify service account by opening “services.msc”, and checking the “Microsoft “Geneva” Server” log on account)
Happy auditing!
