Auditing Access to files??

From: Dan (.)
Date: 03/26/03


From: "Dan" <.>
Date: Wed, 26 Mar 2003 12:14:11 -0700


I have set up object access auditing on a member server for access to files
only. Within about 10 minutes I will get 8000 + entries in the Security
Log, most of which have the info shown below.

Does anyone know what all this means? I only want to audit access to files,
not all this stuff. What am I missing?

Thanks,

Dan

Security Log Event Info:

Handle Closed:
Object Server: Security

Handle ID: 1040

Process ID: 2048

OR

Object Open:

Object Server: Security

Object Type: File

Object Name:
\Device\HarddiskDmVolumes\PhysicalDmVolumes\BlockVolume3\MSSQL7\Binn\sqlmang
r.exe

New Handle ID: 1040

Operation ID: {0,251967762}

Process ID: 2048

Primary User Name: Administrator

Primary Domain: MY DOMAIN

Primary Logon ID: (0x0,0x13B73)

Client User Name: -

Client Domain: -

Client Logon ID: -

Accesses SYNCHRONIZE

Execute/Traverse

Privileges -

OR

Object Open:

Object Server: Security

Object Type: File

Object Name: \??\NAVAP

New Handle ID: 1208

Operation ID: {0,251967718}

Process ID: 992

Primary User Name: SQL1$

Primary Domain: MY DOMAIN

Primary Logon ID: (0x0,0x3E7)

Client User Name: -

Client Domain: -

Client Logon ID: -

Accesses READ_CONTROL

SYNCHRONIZE

ReadData (or ListDirectory)

WriteData (or AddFile)

AppendData (or AddSubdirectory or CreatePipeInstance)

ReadEA

WriteEA

ReadAttributes

WriteAttributes

Privileges -



Relevant Pages

  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: Routing and Remote Access - Authentication Failure
    ... because the real client computer can tunel through it's local NAT router, ... travel the Intrenet, join the VPN and access the server, when this feature ... Their security system decided that the server was trying to steel ...
    (microsoft.public.windows.server.networking)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: Problems with security requirements in Windows WorkGroups.
    ... "A remote side security requirement was not fulfilled during authentication. ... small chat application between a client and a server ... When I try to use the TCP channel I get the error (with NO inner exception ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: VPN -- the next consumer "turnkey"?
    ... I'm not a security expert. ... "A Hamachi system is comprised of backend servers and end-node ... Server nodes track client's locations and provide ... services without providing Hamachi with a list of client IP's. ...
    (alt.internet.wireless)