enable folder audit causes a lot of events 560 562

R

ronkot

Hi,

I would like setting the auditing for a specific folder,
only one. Then I first enabled auditing of object access
by Domain Controller Policy. After (and not set audit
folder yet) I had a lot of events in the security log and
substantially increase the size of the security log. There
are many, many repeatedly events 560, 562. How can I stop
them?
I would like to see only folder access on security log. I
know that I could filter them by event viewer filter, but
I really would stop them for not have a increase server
memory and processing.

Thanks lot

Ronkot
 
S

Steven L Umbach

You can't as far as I know. Just make sure that in security policy you have the
security option for "audit access of global objects" disabled which is the default.
Also be sure to audit the bare minimum of access permissions and avoid using the
everyone group as a group to audit for access attempts. --- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top