Auditing Access to files??

From: Dan (.)
Date: 03/26/03


From: "Dan" <.>
Date: Wed, 26 Mar 2003 12:14:11 -0700


I have set up object access auditing on a member server for access to files
only. Within about 10 minutes I will get 8000 + entries in the Security
Log, most of which have the info shown below.

Does anyone know what all this means? I only want to audit access to files,
not all this stuff. What am I missing?

Thanks,

Dan

Security Log Event Info:

Handle Closed:
Object Server: Security

Handle ID: 1040

Process ID: 2048

OR

Object Open:

Object Server: Security

Object Type: File

Object Name:
\Device\HarddiskDmVolumes\PhysicalDmVolumes\BlockVolume3\MSSQL7\Binn\sqlmang
r.exe

New Handle ID: 1040

Operation ID: {0,251967762}

Process ID: 2048

Primary User Name: Administrator

Primary Domain: MY DOMAIN

Primary Logon ID: (0x0,0x13B73)

Client User Name: -

Client Domain: -

Client Logon ID: -

Accesses SYNCHRONIZE

Execute/Traverse

Privileges -

OR

Object Open:

Object Server: Security

Object Type: File

Object Name: \??\NAVAP

New Handle ID: 1208

Operation ID: {0,251967718}

Process ID: 992

Primary User Name: SQL1$

Primary Domain: MY DOMAIN

Primary Logon ID: (0x0,0x3E7)

Client User Name: -

Client Domain: -

Client Logon ID: -

Accesses READ_CONTROL

SYNCHRONIZE

ReadData (or ListDirectory)

WriteData (or AddFile)

AppendData (or AddSubdirectory or CreatePipeInstance)

ReadEA

WriteEA

ReadAttributes

WriteAttributes

Privileges -



Relevant Pages

  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: Problems with security requirements in Windows WorkGroups.
    ... "A remote side security requirement was not fulfilled during authentication. ... small chat application between a client and a server ... When I try to use the TCP channel I get the error (with NO inner exception ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: VPN -- the next consumer "turnkey"?
    ... I'm not a security expert. ... "A Hamachi system is comprised of backend servers and end-node ... Server nodes track client's locations and provide ... services without providing Hamachi with a list of client IP's. ...
    (alt.internet.wireless)
  • Re: WCF security advice (and clarification) needed
    ... party to spoof the servers identity when the server is not authenticated ... and whenever a client connects to that webserver he's in fact validating the ... all this HTTP talk mentioned a single security token supported by the ... client (Kerberos or Windows) + server ...
    (microsoft.public.dotnet.framework.webservices)