how to filter the event viewer security log for failed logon?

hendri yu 66 Reputation points
2021-01-20T09:45:35.877+00:00

Dear Expert,

Good Day

I am checking the Windows log - Security in the AD server event viewer. However i don't seem to be able to find any log with failed login. for instance something related to account locked out, etc. Because this log might be required for the audit purpose.

FYI, our AD is running Windows Server 2012 Enterprise.

Thanks
H

Windows for business Windows Server Devices and deployment Configure application groups
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Carl Fan 6,881 Reputation points
    2021-01-20T10:21:06.627+00:00

    Hi H,
    If your GPO is setup to audit logon events, you will be able to find
    the "login denied" events in the Event logs "Security".
    How to Audit Successful Logon/Logoff and Failed Logons in Active Directory
    https://www.lepide.com/blog/audit-successful-logon-logoff-and-failed-logons-in-activedirectory/
    Audit logon events
    https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
    Hope this helps and please help to accept as Answer if the response is useful.
    Best Regards,
    Carl


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.