Auditing and Event Viewer

Posted on 2006-03-21
Last Modified: 2012-08-14
Hello All

We have recently enabled auditing on our file server.  I am noticing that we get quite a few events each time a file is created, deleted, etc.  I have noted that Event ID 560 is associated with a file modification, but I also receive them for other actions.  I need to be able to look at the Event Viewer and know what file was acceessed, in what way and by who.  My question is: how can I definitivley tell which ID is for what action?

Thanks in advance
Question by:IOIT
    LVL 7

    Accepted Solution

    Hi IOIT,

    You may wish to download this freeware Event Log Explorer

    Event Log Explorer allows administrators to view, monitor and analyze events recorded in the Security, System, Application and other logs. The program extends the features of the standard event log viewer by offering detailed filtering capabilities, that allow you to view events by category, event ID, event type, user, as well as by date or keyword match. Event Log Explorer can also export your evnts as HTML or printable text report.

    Hope it helps
    LVL 6

    Assisted Solution

    This page will definitively tell you what ID is for what action:

    Just do a search for "Category: Object access" and it'll show up what the event IDs are.  

    There's also EventCombMT from Microsoft available here (with a couple other handy tools in the package):

    Its a similar kind of tool to the one mentioned above, handy for digging through logs.  And while you're digging through logs, don't forget the awesome Logparser:

    Have fun :)

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    Suggested Solutions

    Title # Comments Views Activity
    AIX Memory Cleanup 1 76
    unable to send emails 3 38
    Hibernate on windows 10 18 54
    Time Machine reports 'Disc Full' 3 18
    Introduction How to create multiboot configuration with XP\Vista and Windows 7 on it? And most important question - how to do this correctly so not to have any kind of nightmares we get when system gets screwed? First of all one should realize t…
    Sometimes a user will call me frantically, explaining that something has gone wrong and they have tried everything (read - they have messed it up more and now need someone to clean up) and it still does no good, can I help them?!  Usually the standa…
    It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now