Windows XP Forums


Reply
Thread Tools Display Modes

Remote WMI Query of Event Log with Non-Administrator Account

 
 
Mike R
Guest
Posts: n/a
 
      10th August 2009
I have a windows service set up on one Windows Server 2003 machine that
sweeps through the event logs of other W2K3 domain computers periodically and
writes specified events from the logs to a database for querying.

The appropriate WMI permissions have been set up so that the domain account
under which the service is running should be able to access the logs on those
computers remotely.

Here are the various scenarios and results:
1) When querying the local machine, the WMI Query returns all expected events.
2) When querying a remote machine, and the service account is added to local
administrators group, the WMI Query returns all expected events.
3) When querying a remote machine, and the service account is not set up as
administrator on that machine, the query simply returns no results.

Usually, if it were an access problem, I would expect to get an Access
Denied error. However, it seems that the user must be part of local
administrators group to be able to actually have events returned, even though
that user does have the appropriate permissions set. Here are the specific
permissions I have set:

1) In DCOM configruation, added permission for Remote Activation and Access
2) In WMI Services, added required access for \root and \root\cimv2.
3) In Local Groups, added the domain account under which the service is
running to groups "DCOM Users" and "Performance Monitor Users".

Any other suggestions on what I can do to be able to query the event logs
remotely without having to assign administrator priviledges to the domain
account for the service?
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Event Viewer Error Message - Windows cannot query DllName registryentry David Pryce Windows XP Embedded 2 19th February 2010 08:03 AM
User account query. Andy Dean Windows XP Configuration 0 12th June 2006 06:58 PM
Disable Remote Desktop for Administrator account.... Barry Windows XP Security 2 8th November 2005 11:40 PM
Remote Desktop Connection Query Boab Windows XP Networking 1 17th September 2003 11:24 AM


All times are GMT. The time now is 11:55 PM.
Windows XP Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26