Solved

Object Access - Security Event Log Failure Audit 560

Posted on 2008-11-01
1
3,700 Views
Last Modified: 2013-12-04
I am runnning Windows Server 2003 with SP 2 and am still getiing multiple instances of this failure audit. I would like to turn off auditing object access but it has be turned on for compliance reasons.
It is always the same object \Device\NetbiosSmb at C:\WINDOWS\system32\svchost.exe that is filling my security log file (two events every minute)

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Object Access
Event ID:      560
Date:            11/1/2008
Time:            10:44:54 AM
User:            NT AUTHORITY\LOCAL SERVICE
Computer:      123
Description:
Object Open:
       Object Server:      Security
       Object Type:      File
       Object Name:      \Device\NetbiosSmb
       Handle ID:      -
       Operation ID:      {0,540101}
       Process ID:      860
       Image File Name:      C:\WINDOWS\system32\svchost.exe
       Primary User Name:      LOCAL SERVICE
       Primary Domain:      NT AUTHORITY
       Primary Logon ID:      (0x0,0x3E5)
       Client User Name:      -
       Client Domain:      -
       Client Logon ID:      -
       Accesses:      SYNCHRONIZE
                  ReadData (or ListDirectory)
                  WriteData (or AddFile)
                  
       Privileges:      -
       Restricted Sid Count:      0
       Access Mask:      0x100003

0
Comment
Question by:eric789
1 Comment
 
LVL 8

Accepted Solution

by:
smilerz earned 500 total points
ID: 22857572
According to <a href="http://www.itnewsgroups.net/group/microsoft.public.windows.server.general/topic8837.aspx">this </a>site, this is expected behavior. " This error appear every 2 minutes on machines where domain users tries to query the status of the indexing service, where this clients have not permission, so it generates a failure audit if audit object access is turned on. You can just turn off auditing of object access or, you can turn off auditing on that specific service. In Group policy, go to Computer Configuration -> Windows Settings -> Security Settings -> System Services. Double click the indexing service, set it to disabled, and then click Edit Security. At this point there are two options, you can give the users who this is happening to permission to the service, or you can go into auditing and remove auditing for everyone for failed events (which is on by default on all services)." You can turn off failure just for that object if you want to eliminate that error - otherwise I think you are stuck.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question