Event ID/Source search
Keyword searchExample: Windows cannot unload your registry file
Event ID: 5 Source: GFI EventsManager
|Source: GFI EventsManager|
<?xml version="1.0" encoding="utf-16"?>
<CheckResults xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<string>System events SUCCESS AUDIT not enabled
Object Access events SUCCESS AUDIT not enabled
Privilege use events SUCCESS AUDIT not enabled
Process tracking events SUCCESS AUDIT not enabled
Directory service access events SUCCESS AUDIT not enabled
|English: Request a translation of the event description in plain English.|
These events are recorded by GFI EventsManager on the target machine when a configured audit fails. These audits can be turned off in the Event Sources Groups by right clicking a computer group or a particular computer, and selecting Properties -> Audit tab. In this particular case you're looking for "Check audit policy". Uncheck it and you're done.
This type of event is recorded by GFI EventsManager log monitoring software and it notifies the administrator that certain audit policies that EventsManager consider important are not enabled on that computer. This event is usually followed by event id 7 and event id 1 also from EventsManager. If the computer monitored is part of a "Real-time" schedule scanning (such as the one configured for domain controllers) then this events will be recorded every 5 seconds.
For example, for the information recorded in the sample event description above, the following information is meaningful (the rest is just XML formatting):
The audit of "Success Audit" events is NOT enabled for the following type of security events:
System, Object Access, Privilege use, Process tracking and Directory service.
In our case, we set the scheduled scanning interval to 59 minutes as we did not want to enable all the "Success Audit" events as these can really fill the logs with events that are not always useful and should be used mostly for troubleshooting when applicable.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated