Re: Audit Object Access Problem

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/26/05

  • Next message: Steven L Umbach: "Re: Recovering Encrypted File on WIndows XP workstation"
    Date: Tue, 25 Jan 2005 20:35:46 -0600
    
    

    Jason.

    I am at a loss as to why you are seeing that many events if auditing of
    global objects is disabled and you are sure that no folders are enable for
    auditing. For Windows 2000 computers make sure it shows as disabled for
    "effective" setting in Local Security Policy. I could understand that a lot
    of events would be reported on a domain controller or busy server but not a
    workstation. --- Steve

    "JayJ" <jmcinnes@mighty.co.za> wrote in message
    news:1106664662.041032.49180@f14g2000cwb.googlegroups.com...
    > Hi Steven
    >
    > Thanks for the reply.
    >
    > I'm seeing thousands of entries per minute, even though the option you
    > describe is disabled (access of global system objects). Do you know
    > what could be causing entries like
    > \Device\{29633AC7-C9B6-407B-8FE3-D079B0304CA3} to be audited? 99% of
    > the entries are these \Device\ ones.
    >
    > Thanks
    >
    > Jason
    >


  • Next message: Steven L Umbach: "Re: Recovering Encrypted File on WIndows XP workstation"

    Relevant Pages

    • Re: Cannot Audit hkey_classes_root
      ... Entries in HKCU take precedence in the event of a duplication. ... | anyone for auditing. ... | from the top folder to all the other subkeys for example ...
      (microsoft.public.windows.server.general)
    • Re: Security event logs
      ... If you are auditing what you want/need, the size is what you get. ... AFAIK there is no way to say "Audit logon success and failure, ... Windows put tens thousand plus entries per day into the security log. ...
      (microsoft.public.windows.group_policy)
    • Auditing at the files level
      ... to turn of auditing at the file level. ... reports entries in the event log. ...
      (microsoft.public.win2000.security)
    • Stop auditing please
      ... We had a security issue a few weeks back and I enabled audits on the network ... I was auditing logon/logoff and all file or folder deletions. ... more entries per minute. ... Since hexadecimal security codes mean nothing to me, ...
      (microsoft.public.win2000.security)

  • Quantcast