Link to home
Start Free TrialLog in
Avatar of Declan Basile
Declan BasileFlag for United States of America

asked on

Understanding Security Log Events

I turned both Success and Failure monitoring on for "Audit object access" in the "Local Group Policy Editor" of a Windows Storage 2008 R2 Server.  Why would a client computer that's *apparently* just sitting idle and not running any programs constantly get logged in the security log as "A network share object was checked to see whether client can be granted desired access."?  First of all, why would the computer be trying to access the network share?  And secondly, even if it is accessing the network share, why would it get logged if I didn't turning set any user activity to get logged in the security properties of that network share?
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Declan Basile

ASKER

Thank you very much!