?
Solved

Object Access - Security Event Log Failure Audit 560

Posted on 2008-11-01
1
Medium Priority
?
3,738 Views
Last Modified: 2013-12-04
I am runnning Windows Server 2003 with SP 2 and am still getiing multiple instances of this failure audit. I would like to turn off auditing object access but it has be turned on for compliance reasons.
It is always the same object \Device\NetbiosSmb at C:\WINDOWS\system32\svchost.exe that is filling my security log file (two events every minute)

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Object Access
Event ID:      560
Date:            11/1/2008
Time:            10:44:54 AM
User:            NT AUTHORITY\LOCAL SERVICE
Computer:      123
Description:
Object Open:
       Object Server:      Security
       Object Type:      File
       Object Name:      \Device\NetbiosSmb
       Handle ID:      -
       Operation ID:      {0,540101}
       Process ID:      860
       Image File Name:      C:\WINDOWS\system32\svchost.exe
       Primary User Name:      LOCAL SERVICE
       Primary Domain:      NT AUTHORITY
       Primary Logon ID:      (0x0,0x3E5)
       Client User Name:      -
       Client Domain:      -
       Client Logon ID:      -
       Accesses:      SYNCHRONIZE
                  ReadData (or ListDirectory)
                  WriteData (or AddFile)
                  
       Privileges:      -
       Restricted Sid Count:      0
       Access Mask:      0x100003

0
Comment
Question by:eric789
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 8

Accepted Solution

by:
smilerz earned 1500 total points
ID: 22857572
According to <a href="http://www.itnewsgroups.net/group/microsoft.public.windows.server.general/topic8837.aspx">this </a>site, this is expected behavior. " This error appear every 2 minutes on machines where domain users tries to query the status of the indexing service, where this clients have not permission, so it generates a failure audit if audit object access is turned on. You can just turn off auditing of object access or, you can turn off auditing on that specific service. In Group policy, go to Computer Configuration -> Windows Settings -> Security Settings -> System Services. Double click the indexing service, set it to disabled, and then click Edit Security. At this point there are two options, you can give the users who this is happening to permission to the service, or you can go into auditing and remove auditing for everyone for failed events (which is on by default on all services)." You can turn off failure just for that object if you want to eliminate that error - otherwise I think you are stuck.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question