Solved

Parameters list in Security Event ID 4663

Posted on 2013-12-10
4
893 Views
Last Modified: 2013-12-10
I'm trying to alert when files are deleted in a folder. I turned on auditing for deletes and I see event id 4663 in the security log.  I'm using SCOM 2012 to comb the event log.  

What I need to know is what is the parameters values for this alert.

Specifically, what parameter value is the "DELETE" value.
 

Access Request Information:
      Accesses:      DELETE
0
Comment
Question by:jalenk
  • 2
  • 2
4 Comments
 
LVL 19

Accepted Solution

by:
jss1199 earned 500 total points
ID: 39710165
String01 – Object Type
String02 – Object Name
String03 – Process ID
String04 - Process Name
String05 – Accesses
String06 – Object Server
String07 – Handle ID
String08 – Transaction ID
String09 – Access Mask
String10 – Privileges Used for Access Check
String11 – Restricted SID Count

For your example, you want alert when String 05 contains DELETE
0
 

Author Comment

by:jalenk
ID: 39710170
Thanks.  How did you figure that out? I'll need the same list for event id 4660
0
 

Author Closing Comment

by:jalenk
ID: 39710173
quick!
0
 
LVL 19

Expert Comment

by:jss1199
ID: 39710227
I have it memorized from years of SCOM and ACS :)

The easiest way is to open the event you are concerned about in event viewer, select the copy command.  Paste the contents into notepad and you will have the XMLdata of the event.

If you look under the EventData section, you'll notice a number of <Data Name=".... Each of those is a string and can be referred to as String01, String02, String03, in order, until you reach the end..
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now