locked
File auditing Logs RRS feed

  • Question

  • does any one  know why it the attached snap shot don't give the exact details, that who have accessed the file, who edited and when file has accessed. As i did standard configuration, as per Microsoft instruction. looking to your advice, support and comments. thanks
    Friday, September 18, 2015 6:56 PM

Answers

  • Hi Shoaib Momand,

    Thanks for your post.

    Based on my research, Event 5140 means a network share object was accessed, which is a normal Audit File Share Event.

    Please refer to the article for more details.

    https://technet.microsoft.com/en-us/library/dd772690%28v=WS.10%29.aspx?f=255&MSPPError=-2147217396

    In you event log, the share information refer to the file. If you want to see who access, you may find in Subject in the event log. You may find the Security ID and Account NameYou could also Enabling Object Access. Object Access policy settings and audit events allow you to track attempts to access specific objects or types of objects on a network or computer.

    Auditing File Access on File Servers

    http://blogs.technet.com/b/mspfe/archive/2013/08/27/auditing-file-access-on-file-servers.aspx

    Advanced Security Audit Policy Settings

    https://technet.microsoft.com/en-us/library/dn319056.aspx

    Best Regards,

    Mary Dong


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Proposed as answer by Mary Dong Wednesday, September 30, 2015 1:37 AM
    • Marked as answer by Mary Dong Friday, October 2, 2015 1:17 AM
    Monday, September 21, 2015 5:21 AM
  • The above suggestions looks good to accomplish this job.  Moreover, If you wish you may also take help from below given informative references that might helps you to get in more details:

    Checkout this article to fix the event log service not start, you can check it for some reference: http://www.thewindowsclub.com/windows-event-log-service-not-starting

    On the other hand, if you want to track such changes automatically, you may also check this automated solution i.e. http://www.fileserveraudit.com/ which lets you about who is changing what, where and when modifications are carried out in files, folders, servers and filer systems.

    • Proposed as answer by Mary Dong Wednesday, September 30, 2015 1:37 AM
    • Marked as answer by Mary Dong Friday, October 2, 2015 1:17 AM
    Monday, September 21, 2015 7:29 AM

All replies