WMF 5.0 DSC ConfigurationStatus Folder Permissions

Welcome Forums DSC (Desired State Configuration) WMF 5.0 DSC ConfigurationStatus Folder Permissions

This topic contains 4 replies, has 3 voices, and was last updated by

 
Participant
2 years, 3 months ago.

  • Author
    Posts
  • #54924

    Participant
    Points: 0
    Rank: Member

    Hi ,

    I'm trying to use ElasticSearch to send logs from C:\Windows\System32\Configuration\ConfigurationStatus .

    Filebeat which is the part of ElasticSearch is running as a service under Local System account .

    When I copy ConfigurationStatus Folder to C drive and point filebeat to send those logs it works .

    Is there some extra security settings on "C:\Windows\System32\Configuration\ConfigurationStatus" that prevents the access ?

    Regards

    Mariusz

  • #54942

    Participant
    Points: 0
    Rank: Member

    Yes it has different security settings than default system settings. You can see the security settings using get-acl

    (get-acl $env:windir\system32\configuration\configurationstatus).AccessToString
    
  • #54971

    Participant
    Points: -19
    Rank: Member

    @Nitin: Isn't the LCM itself running as local system ?
    why would then, other services using local system, have issues accessing that folder ?

  • #54981

    Participant
    Points: 0
    Rank: Member

    Yes, LCM is running as Local System and any process/service running as Local System can access ConfigurationStatus folder. I was trying to make a point that this folder has different security settings than System32 folder.
    I am able to copy the files as Local System outside of DSC using Task scheduler. I am not sure how Filebeat is copying files though.

  • #55073

    Participant
    Points: 0
    Rank: Member

    I had to share "C:\Windows\System32\Configuration\ConfigurationStatus" folder and then point filebeat to \\localhost\ and the logs appeared in ElasticSearch !!

    Thanks for help !

    Regards

    Mariusz

The topic ‘WMF 5.0 DSC ConfigurationStatus Folder Permissions’ is closed to new replies.