Hi,
I have created a VM with Windows server 2012r2 on a VMware platform (member server). The machine hardware is on an NAS device. I have created a shared folder on the machine and enabled auditing access for all users (success and failure.) in addition, I have created the group policy, edited security and linked the policy to the O.U in which this machines resides.
I have accessed the shared folder on numerous occasions, however in the event viewer on the local server, I receive the following information:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 04/03/2016 11:36:23
Event ID: 4719
Task Category: Audit Policy Change
Level: Information
Keywords: Audit Success
User: N/A
Computer:
System audit policy was changed.
Subject:
Security ID: SYSTEM
Account Name:
Account Domain:
Logon ID: 0x3E7
Audit Policy Change:
Category: Object Access
Subcategory: Other Object Access Events
Subcategory GUID: {0cce9227-69ae-11d9-bed3-505054503030}
Changes: Success removed, Failure removed
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4719</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>13568</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2016-03-04T11:36:23.743506400Z" />
<EventRecordID>14370</EventRecordID>
<Correlation />
<Execution ProcessID="476" ThreadID="2848" />
<Channel>Security</Channel>
<Computer>Owlserv08.Owlstone.local</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">OWLSERV08$</Data>
<Data Name="SubjectDomainName">OWLSTONE</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="CategoryId">%%8274</Data>
<Data Name="SubcategoryId">%%12804</Data>
<Data Name="SubcategoryGuid">{0CCE9227-69AE-11D9-BED3-505054503030}</Data>
<Data Name="AuditPolicyChanges">%%8448, %%8450</Data>
</EventData>
</Event>
There are no events logged on either domain controllers. I have a 1x 2008r2 and 1x 2003 domain controllers
Any help would be appreciated