Turning off event 560

  • Thread starter Thread starter Frank Jones
  • Start date Start date
F

Frank Jones

I get thousands of the below in my security log. It started when I turned
file level auditing on the windows directory and on registry hives. I since
turned auditing off on both - but I continue to get the below.

How do I turn these off?


Event Type: Success Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 8/29/2003
Time: 5:13:21 PM
User: MYSERVER\Administrator
Computer: MYSERVER
Description:
Object Open:
Object Server: Security
Object Type: File
Object Name: \Device\{D0918481-6A64-4E16-A30A-EA8CFEA7AEE4}
New Handle ID: 1196
Operation ID: {0,22293850}
Process ID: 1264
Primary User Name: Administrator
Primary Domain: MYSERVER
Primary Logon ID: (0x0,0x615BD)
Client User Name: -
Client Domain: -
Client Logon ID: -
Accesses READ_CONTROL
SYNCHRONIZE
ReadData (or ListDirectory)
WriteData (or AddFile)
AppendData (or AddSubdirectory or CreatePipeInstance)
ReadEA
WriteEA
ReadAttributes
WriteAttributes

Privileges -
 
You also need to disable auditing of object access for the computer either in
Local Security Policy or at domain/ou level if it is configure there. --- Steve
 
Back
Top