Desktop.ini auditing filling event logs

Desktop.ini auditing filling event logs

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Desktop.ini auditing filling event logs rcurley 07-29-2005
Posted by rcurley on July 29, 2005, 10:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have enabled auditing on a directory and all of its subdirectories
and files, for a location where users My Documents have been
redirected. I have set auditing for Change Permissions, Take
Ownership, Write Attributes, and Write Extended Attributes. However,
my security log on that machine is being filled with "Object Access"
entries referring to Accesses of ReadAttributes and WriteAttributes.
For the normal user, this is happening for only their redirected
folder. For the few in the domain admins group, there is an Accesses
entry with READ_CONTROL, ReadData (or ListDirectory) and ReadEA in
addition to the previoius two, for everyone's desktop.ini file in their
redirected users. This is really filling up the log files, making
auditing very difficult. Any ideas or help would be greatly
appreciated.

Rich C.


Posted by Eric Fitzgerald [MSFT] on August 22, 2005, 11:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Desktop.ini is a file Explorer always looks for in every directory, telling
it how to display the folder. If you enable auditing on this file or on
directories such as My Documents that users are likely to browse to with
Explorer, you will get a large number of accesses and therefore audit
records.

As a general rule, you should avoid auditing for ReadData and other read
accesses, and you should avoid auditing for WriteAttributes and
WriteExtendedAttributes, as these are very noisy.

Best regards,
Eric

--
This information is provided "AS-IS" with no warranty, and confers no
rights.
>I have enabled auditing on a directory and all of its subdirectories
> and files, for a location where users My Documents have been
> redirected. I have set auditing for Change Permissions, Take
> Ownership, Write Attributes, and Write Extended Attributes. However,
> my security log on that machine is being filled with "Object Access"
> entries referring to Accesses of ReadAttributes and WriteAttributes.
> For the normal user, this is happening for only their redirected
> folder. For the few in the domain admins group, there is an Accesses
> entry with READ_CONTROL, ReadData (or ListDirectory) and ReadEA in
> addition to the previoius two, for everyone's desktop.ini file in their
> redirected users. This is really filling up the log files, making
> auditing very difficult. Any ideas or help would be greatly
> appreciated.
>
> Rich C.
>



Similar ThreadsPosted
Remote access to event logs August 12, 2005, 4:09 pm
event logs : is there a way to save them remotely? November 14, 2005, 12:05 pm
security event logs do not log all failures from OWA ? ? April 17, 2006, 6:37 pm
Remote Security Event Logs March 16, 2007, 4:41 pm
Unusual security event logs October 28, 2008, 3:15 pm
Windows 2003 Server Event Logs January 6, 2006, 10:43 am
Lots of Event Security logs 529?? Explanation Please July 6, 2007, 9:38 am
Re: Viewing Win2k3 Event logs remotely in a Win2k Domain May 26, 2005, 5:50 pm
Security Event Log Performance for File and Folder Auditing January 26, 2007, 3:59 pm
Disks filling up - how to track it July 20, 2005, 10:00 pm

The site map in XML format XML site map

Contact Us | Privacy Policy