Windows 10: Event Log showing wrongly created documents with auditing.

Discus and support Event Log showing wrongly created documents with auditing. in Windows 10 Ask Insider to solve the problem; Hello all, I am having an issue with my event logs showing wrong information when documents are created for auditing whats been deleted and modified in... Discussion in 'Windows 10 Ask Insider' started by /u/Limestone5000, Dec 25, 2019.

  1. Event Log showing wrongly created documents with auditing.


    Hello all, I am having an issue with my event logs showing wrong information when documents are created for auditing whats been deleted and modified in my content. Example:



    I will create a document in my shared drive which power-shell will eventually document when running a Powershell script and porting it into an html file like this... Very basic view below

    An attempt was made to access an object. Subject: Security ID: S-1-5-21-1098493710-3710303698-3917163380-500 Account Name: administrator Account Domain: NTL Logon ID: 0x42F96 Object: Object Server: Security Object Type: File Object Name: E:\Shares\Users\New Text Document.txt Handle ID: 0x3174 Resource Attributes: S:AI Process Information: Process ID: 0x1034 Process Name: C:\Windows\explorer.exe Access Request Information: Accesses: DELETE Access Mask: 0x10000 FILES-RDS.ntechlife.local 4663 12/25/2019 2:40:00 PM Information File System An attempt was made to access an object. Subject: Security ID: S-1-5-21-1098493710-3710303698-3917163380-500 Account Name: administrator Account Domain: NTL Logon ID: 0x42F96 Object: Object Server: Security Object Type: File Object Name: E:\Shares\Users\New Text Document.txt Handle ID: 0x38f0 Resource Attributes: S:AI Process Information: Process ID: 0x1034 Process Name: C:\Windows\explorer.exe Access Request Information: Accesses: WriteData (or AddFile) Access Mask: 0x2

    First off no document named New Text Document.txt was created. I will the new document something like "testing.txt".... I am curious as to why this "New Text Document" would show up and immediately delete itself.



    Side note: When I append data to said document or delete the document it will show the true name of the document in my event logs.

    submitted by /u/Limestone5000
    [link] [comments]

    :)
     
    /u/Limestone5000, Dec 25, 2019
    #1
  2. homer_3 Win User

    Q about audit logs

    When setting up audit logging under Computer Configuration -> Windows Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Logon/Logoff -> Audit Account Lockout, if I enable the Success option, how does this log get triggered? When
    an account is locked out, a failure event is fired under the Account Locked category. But when an account is unlocked, an event is fired under the User Account Management category. How would a successful account lockout event get fired? What would that even
    be?
     
    homer_3, Dec 25, 2019
    #2
  3. Event ID 7036 not showing in Windows Event Log on Win10

    It looks like 7036 event is missing from Windows desktop OS (starting from 8).
    However you can monitor process termination:

    1. Enable Audit Policy to audit process tracking:

    1. Check for event 4689 in Security Event Log

    Alternatively you may try this solution.

    But in this case, you will get event 4546 not only when the service starts or stops, but whenever something is trying to access it (e.g. when Services applet is open).
     
    Michael Karsyan, Dec 25, 2019
    #3
  4. Event Log showing wrongly created documents with auditing.

    Security Event Log flooded with 4656 Events

    We are having issues with our Security event log within Event Viewer. It is my understanding when you perform Object Access auditing and enable it within Group Policy, you still need to enable auditing on the Objects (to be audited) themselves. We just enabled
    Object Access auditing and are already seeing Handle Manipulation events (i.e. event id 4656) flooding our Security log even though we have not configured auditing at the file level for ANY of the files in question.
    A lot of forums mention disabling Audit File System and Audit Handle Manipulation events to ensure the 4656 events do not flood the Security log; however, we want to be able to see these events for the files that we configure auditing for (at the
    file level), but not for any other files which were not configured for auditing at the file level.
    We do not have Global Object Access Auditing configured.
     
    iggygatton, Dec 25, 2019
    #4
Thema:

Event Log showing wrongly created documents with auditing.

Loading...
  1. Event Log showing wrongly created documents with auditing. - Similar Threads - Event Log showing

  2. Excessive "Audit Success" log events for event ID 5061 and 5058

    in Windows 10 Gaming
    Excessive "Audit Success" log events for event ID 5061 and 5058: I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.Anyone else seeing this? Wondering whether I can/need to update my Audit...
  3. Excessive "Audit Success" log events for event ID 5061 and 5058

    in Windows 10 Software and Apps
    Excessive "Audit Success" log events for event ID 5061 and 5058: I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.Anyone else seeing this? Wondering whether I can/need to update my Audit...
  4. Event logs Audit Failure tracking

    in Windows 10 Gaming
    Event logs Audit Failure tracking: Hi guys,Today when i was inspecting security event logs at active directory server i realised we are recieving constant password brute force attacks from different user accounts.Usernames were seeming to be coming from a rainbow table as; Jessie, Jaxon, Clare...so onSource...
  5. Event logs Audit Failure tracking

    in Windows 10 Software and Apps
    Event logs Audit Failure tracking: Hi guys,Today when i was inspecting security event logs at active directory server i realised we are recieving constant password brute force attacks from different user accounts.Usernames were seeming to be coming from a rainbow table as; Jessie, Jaxon, Clare...so onSource...
  6. Disable auditing of successful events

    in Windows 10 Performance & Maintenance
    Disable auditing of successful events: This command worked Code: auditpol /Set /Caregory:* /success:disable I need to check event log, if there are reported any longer successful events. Problem is overall: there are too many categories to check manually. I ran this command: Code: auditpol /Get /Category:* And it...
  7. What these audits logs in event viewer?

    in AntiVirus, Firewalls and System Security
    What these audits logs in event viewer?: My audit logs seems to be all turned off: [ATTACH] I would like some explanation on these why am I seeing "logon" events if they are turned off? [ATTACH] Can we turn these on / off and how? PS: I understand turning these off are probably idea, but since I am...
  8. Audit logs

    in Windows 10 Customization
    Audit logs: I have my various logs set via group policy. I would like to verify that I am actually getting the logs. If action has not happened. I would like to figure out how to generate that particular log setting. Ex: I want to generate Event ID 4727,2735,4737,4754,4758,and 4764....
  9. Audit Lock/Unlock events

    in AntiVirus, Firewalls and System Security
    Audit Lock/Unlock events: I know how to enable advanced auditing for other logon-logoff events in order to catch lock/unlocking of a Windows computer. See link for reference:...
  10. Windows Audit Log

    in AntiVirus, Firewalls and System Security
    Windows Audit Log: I work as a Security Analyst, I have been going through the windows logs of a client organization. Where there's a lot of login success event at off times. I would like to know, how to differentiate between a login attempt is an actual login or just some services getting...