Re: Audit failures from explorer.exe

From: Jan Bares (jan.bares_at_nospam.nospam)
Date: 03/07/05


Date: Mon, 7 Mar 2005 09:46:42 +0100

Thank Steven,

does Event Comb support to filter out (don't show them) events from specific
process ID? So I can filter out 560 events created by explorer?
The problem is, that events doesn't contain name of executable, only process
ID, so any filtering after explorer was restarted will not help.

Jan

"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:ONjG5WnIFHA.236@TK2MSFTNGP14.phx.gbl...
> I have noticed the same thing and there is no way to selectively disable
> auditing of explorer.exe. You might find that using Event Comb can help to
> filter security log searches to find more specific information and events.
> Event Comb allows you to search based on text strings and event ID's.



Relevant Pages

  • Re: Audit failures from explorer.exe
    ... The best way to see if Event Comb suits your needs is to try it out as it is ... string to search for within those events. ... So I can filter out 560 events created by explorer? ...
    (microsoft.public.win2000.security)
  • Re: how do i print multiple documents on a sharepoint website?
    ... Your suggestion ... would be very helpful if we were dealing with a smaller number of documents. ... Using Explorer ... document to its proper print group and we can filter on that column to ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Assigning a drive letter to com port
    ... extension, no FS filter. ... system driver you should get Rajeev Nagars book "Windows NT File System ... In Windows Explorer, ...
    (microsoft.public.development.device.drivers)
  • Re: Assigning a drive letter to com port
    ... if you just want this to work in explorer, you can write a shell namespace ... extension, no FS filter. ... > system driver you should get Rajeev Nagars book "Windows NT File System ... >> In Windows Explorer, ...
    (microsoft.public.development.device.drivers)
  • Re: Audit failures from explorer.exe
    ... Event Comb allows you to search based on text strings and event ID's. ... > I know the reason why Explorer does this. ... > for a folder, this results in a call to NtCreateFile. ... There is a function that can return rights on ...
    (microsoft.public.win2000.security)