Jump to content

Recommended Posts

Posted

Hi

My server is running on windows 2003 server. As this is a file server, i need to perform auditing on file accesses.

After I have enabled the object access item in the local security policy, I discovered that there are a lot of 562 and 567 entries generated in the event log. This cause the event log to grow very fast. As I can only manage the server remotely via VNC, there are many VNC entries generated every few seconds. This causes the event log to become full.

These are the common 2 entries

Event Type: Success Audit

Event Source: Security

Event Category: Object Access

Event ID: 562

Date: 9/6/2005

Time: 5:57:30 PM

User: NT AUTHORITY\SYSTEM

Computer: ZENITH2K2

Description:

Handle Closed:

Object Server: Security

Handle ID: 248

Process ID: 3760

Image File Name: C:\Program Files\RealVNC\VNC4\winvnc4.exe

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Success Audit

Event Source: Security

Event Category: Object Access

Event ID: 567

Date: 9/6/2005

Time: 5:57:30 PM

User: NT AUTHORITY\SYSTEM

Computer: ZENITH2K2

Description:

Object Access Attempt:

Object Server: Security

Handle ID: 248

Object Type: Desktop

Process ID: 3760

Image File Name: C:\Program Files\RealVNC\VNC4\winvnc4.exe

Accesses: Read Objects

Access Mask: 0x1

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

May I know is there any settings that I can configure in the security policy to prevent such entries?

Thank you.


Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...