Turning off event 560

From: Frank Jones (jones_at_jonsey.com)
Date: 08/29/03


Date: Fri, 29 Aug 2003 17:12:21 -0400


I get thousands of the below in my security log. It started when I turned
file level auditing on the windows directory and on registry hives. I since
turned auditing off on both - but I continue to get the below.

How do I turn these off?

Event Type: Success Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 8/29/2003
Time: 5:13:21 PM
User: MYSERVER\Administrator
Computer: MYSERVER
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: \Device\{D0918481-6A64-4E16-A30A-EA8CFEA7AEE4}
  New Handle ID: 1196
  Operation ID: {0,22293850}
  Process ID: 1264
  Primary User Name: Administrator
  Primary Domain: MYSERVER
  Primary Logon ID: (0x0,0x615BD)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses READ_CONTROL
   SYNCHRONIZE
   ReadData (or ListDirectory)
   WriteData (or AddFile)
   AppendData (or AddSubdirectory or CreatePipeInstance)
   ReadEA
   WriteEA
   ReadAttributes
   WriteAttributes

  Privileges -



Relevant Pages

  • MSDTC Security Log Failure Audits
    ... While scrolling through the Security logs of a Windows 2003 box, ... Event Type: Failure Audit ... Primary Logon ID: ... Client User Name: - ...
    (microsoft.public.windows.server.security)
  • Re: Ntbackup Windows 2003 SP1 issue (VSS/Security)
    ... the Users group on the machine where the access is throwing ... Microsoft MVP (Windows Security) ... > Primary Logon ID: ... > Client Domain: VLM ...
    (microsoft.public.windows.server.security)
  • WwK3 cluster + MSSQL sp3a upg.
    ... the setup for MS SQL sp3a it stops saying that it cannot detect the satus of ... We have applied a security template which might conflict with MS ... Primary Logon ID: ... Client User Name: NETWORK SERVICE ...
    (microsoft.public.sqlserver.clustering)
  • Re: 560 errors
    ... security policy. ... > Event Type: Failure Audit ... > Primary Logon ID: ... > Client User Name: - ...
    (microsoft.public.win2000.security)
  • Re: Why does this keep happening...
    ... here's what's showing up in my security log in the event ... Object Server: Security ... Primary Logon ID: ... Client User Name: - ...
    (microsoft.public.inetserver.iis.security)