enable folder audit causes a lot of events 560 562

  • Thread starter Thread starter ronkot
  • Start date Start date
R

ronkot

Hi,

I would like setting the auditing for a specific folder,
only one. Then I first enabled auditing of object access
by Domain Controller Policy. After (and not set audit
folder yet) I had a lot of events in the security log and
substantially increase the size of the security log. There
are many, many repeatedly events 560, 562. How can I stop
them?
I would like to see only folder access on security log. I
know that I could filter them by event viewer filter, but
I really would stop them for not have a increase server
memory and processing.

Thanks lot

Ronkot
 
You can't as far as I know. Just make sure that in security policy you have the
security option for "audit access of global objects" disabled which is the default.
Also be sure to audit the bare minimum of access permissions and avoid using the
everyone group as a group to audit for access attempts. --- Steve
 
Back
Top