Jump to content

Recommended Posts

Posted

Hi

My server is running on windows 2003 server. As this is a file server, i need to perform auditing on file accesses.

After I have enabled the object access item in the local security policy, I discovered that there are a lot of 562 and 567 entries generated in the event log. This cause the event log to grow very fast. As I can only manage the server remotely via VNC, there are many VNC entries generated every few seconds. This causes the event log to become full.

These are the common 2 entries

Event Type: Success Audit

Event Source: Security

Event Category: Object Access

Event ID: 562

Date: 9/6/2005

Time: 5:57:30 PM

User: NT AUTHORITY\SYSTEM

Computer: ZENITH2K2

Description:

Handle Closed:

Object Server: Security

Handle ID: 248

Process ID: 3760

Image File Name: C:\Program Files\RealVNC\VNC4\winvnc4.exe

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Success Audit

Event Source: Security

Event Category: Object Access

Event ID: 567

Date: 9/6/2005

Time: 5:57:30 PM

User: NT AUTHORITY\SYSTEM

Computer: ZENITH2K2

Description:

Object Access Attempt:

Object Server: Security

Handle ID: 248

Object Type: Desktop

Process ID: 3760

Image File Name: C:\Program Files\RealVNC\VNC4\winvnc4.exe

Accesses: Read Objects

Access Mask: 0x1

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

May I know is there any settings that I can configure in the security policy to prevent such entries?

Thank you.


Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...