Desktop.ini auditing filling event logs

From: rcurley (rcurley_at_stewartmarchman.org)
Date: 07/29/05


Date: 29 Jul 2005 07:33:37 -0700

I have enabled auditing on a directory and all of its subdirectories
and files, for a location where users My Documents have been
redirected. I have set auditing for Change Permissions, Take
Ownership, Write Attributes, and Write Extended Attributes. However,
my security log on that machine is being filled with "Object Access"
entries referring to Accesses of ReadAttributes and WriteAttributes.
For the normal user, this is happening for only their redirected
folder. For the few in the domain admins group, there is an Accesses
entry with READ_CONTROL, ReadData (or ListDirectory) and ReadEA in
addition to the previoius two, for everyone's desktop.ini file in their
redirected users. This is really filling up the log files, making
auditing very difficult. Any ideas or help would be greatly
appreciated.

Rich C.



Relevant Pages

  • Re: EventID 560, how do I clean it up
    ... IUSR_xxx events are generated when IIS accesses a file that you have set ... auditing on. ... You should review the auditing settings you have set, ... don't audit accesses that you're not interested in. ...
    (microsoft.public.win2000.security)
  • Re: Desktop.ini auditing filling event logs
    ... it how to display the folder. ... If you enable auditing on this file or on ... you will get a large number of accesses and therefore audit ... you should avoid auditing for ReadData and other read ...
    (microsoft.public.security)
  • Re: Authentication Auditing
    ... > only show in the security log of the domain computer itself - not the ... > it indeed does show that auditing of logon events is enabled for success ... It is enabled but the effective setting dispalys as "No Auditing". ...
    (microsoft.public.win2000.security)
  • Re: Audit Failures/READ_CONTROL SYNCHRONIZE
    ... You're auditing File and Object Access; you've enabled Auditing on the files ... and you're complaining about audit events ... You can't mask events out of the security log in Event Viewer. ... > Client Domain: HEX21 ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Monitor User Remotely.
    ... activity, auditing of process tracking on ... remotely via administrator share, and folder files have creation timestamps ... he can clear the security log. ... > Is there any way we can remotely monitor him, ...
    (microsoft.public.win2000.security)