Z
Z
Zakharov Alexander2016-06-11 22:04:07
System administration
Zakharov Alexander, 2016-06-11 22:04:07

windows server 2012 audit log no file delete event 4660?

Hello.
It is not possible to deal normally with the logging of file deletion events on Windows Server 2012 R2 x64. You need to configure the windows security log to log file deletion events. According to all the instructions, it is enough to do: And you don’t even need to overload. Now you need to set up auditing of directory events: Well, as usual, you need to check this. I delete a file: Now in theory I should receive the following events 4656/4663 for a deletion request (descriptor request), but the final deletion is registered in event 4660. So there are 4656 and 4663 in the log, but 4660 is missing: Just in case, I did the following checks: - checked the security log filter - no filters installed.
e1249c96b40a47ecb6e8ddce6ba26e9f.png
d0ecc97767924edf8bb10decbe7e8048.png
47c2652bfa144069a9f1287f8b7a717e.png
6e021ebfa8c8462688bec89d188ed9b2.png
- I checked the operation of the same settings on another windows server 2012 R2 server.
- the file is definitely deleted on the local drive.
The result has not changed and there are still no 4660 events. 4660 looks like this: On windows 8.1 corporate everything works fine and 4660 events are logged normally. Do not tell me - what did I miss?
34f113edbc4a4a71a53ce678c91114c8.png

Answer the question

In order to leave comments, you need to log in

1 answer(s)
P
PanPancho, 2020-09-08
@PanPancho

event 4659

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question