Audit logs on Windows 2008 works different when file is modified from UNC path

Hello All,
Here i have a strange situation with the generation of audit logs when folders\files are changed locally(my computer) on the server (vs) from the UNC path
(\\servername\drive$\folder\....).
File Server : Windows 2008 R2.
Audting enabled and SACL set on the folder level.
Enabled advanced auditing for Audit Object Access and enabled the force sub category audit settings on vista \ window 2008 policy via GPO and also verified that the sub category is set.
also set SACL on one folder on the R drive. (\\servername\r$\<folder>\<audited folder>
auditpol /get /category:"Object Access"
Object Access : File System                            
Success and Failure
Situation : 1
When i make any manipulations (traversing \ listing \ adding or deleting folder or files) on the server locally from my computer ---> . r drive --> folder --> audited folder , i get the event id generated (4663) with all the correct
information.
For ex: created a new txt file.
Object: Object Server: Security, Object Type: File, Object Name: R:\Audits1\folder1\New Text Document.txt, Handle ID: 0xcb4
Process Information: Process ID: 0x1bac , Process Name: C:\Windows\explorer.exe
Access Request Information: Accesses: WriteData (or AddFile) AppendData (or AddSubdirectory or CreatePipeInstance) , Access Mask: 0x6
Situation : 2
When i make the same  manipulations (traversing \ listing \ adding or deleting folder or files) on the server or remotely via the UNC path \\servername\r$\folder\audited folder or DFS share or \\servername\<sharename>
, i dont get the event id generated (4663) with the needed information.
For ex: created a new txt file.
Object: Object Server:      
Security , Object Type:File ,         
Object Name:         
R:\Audits1\folder1\New Rich Text Document (3).rtf , Handle ID:  
0xa3c
Process Information: Process ID: 0x4, Process Name:
Access Request Information: 
Accesses: WriteData(or addfile), Access Mask: 0x100
In the second situation process name is empty (for the file events) and also found that the logs generated are very less compared to the first situation.
Please suggest if there is any fix with this.
Thanks,

Enable the following auditing on the server either through domain
policy or local policy:
Audit logon events - Success
Audit Object Access  - Success
On the Auditing tab, add Everyone with the following audit settings.

Similar Messages

  • PS script file works differently when scheduled vs run from Powershell

    The following script works when run from PowerShell window.
    The script does not work when ran as scheduled task.   The email part works fine, however the body is blank.    It also does not update the timeran.txt file.
    MORE INFO ADDED:     the script is scheduled on the Hyper-V host box.  user is Domain Administrator equivalent.     OS is server w2k12.     TASK  CONFIG:   user is domain\Adminequivalent.   
    Run whether user is logged in or not.      trigger is 7:00 AM.     Action is   Powershell        argument is  .\scriptname.ps1      Start
    in  is   C:\scripts
    TIA..   bob
    # Variables
     $filedate = get-date
     $computer = gc env:computername
     $FromEmail = "[email protected]"
     $ToEmail = "[email protected]"
     # Establish Connection to SMTP server
     $smtpServer = "mail.mydomain.com"
     $smtp = new-object Net.Mail.SmtpClient($smtpServer)
      get-date | Out-File  "C:\Util\timeran.txt" -append
      Measure-VMReplication -ComputerName Hyp-03 | Select Name,Health,LreplTime | ConvertTo-Html | Out-File "C:\Util\report.html"
      $a = Get-Content C:\Util\report.html
    #  email  
     $email = new-object Net.Mail.MailMessage
     $email.Subject = "$($computer) Replication Report: $($filedate)"
     $email.From = new-object Net.Mail.MailAddress($FromEmail)
     $email.Sender = new-object Net.Mail.MailAddress($FromEmail)
     $email.IsBodyHtml = $true
     $email.Body = $a
     $email.To.Add($ToEmail)
     # Send Email
     $smtp.Send($email)
    Bob Lee

    Hi Bob,
    It seems this cmdlet "Get-Content C:\Util\report.html" in the script didn't work in the task scheduler, as Mike said please make sure you have check the option "Run with the highest privileges".
    In addition, I also would like to know if your current logon account is domain admin, I tested with the setting below and ran the task without issue, the TASK  CONFIG: The user domain\Anna is in local administrators group:
    If there is anything else regarding this issue, please feel free to post back.
    If you have any feedback on our support, please click here.
    Best Regards,
    Anna
    TechNet Community Support

  • TableView LINEEDIT works differently when viewed through Portal

    I have a simple table with a few columns of data that I display and allow the user to change a row using the selectionMode = "lineedit".  The columns are all controlled using htmlb tableViewColumns.
    When I test my application from the WebAs the table looks fine.  If a user selects a row they can see the entire amount of text that appears in a column they want to change
    However, when the BSP comes up in our SAP portal and the user selects a row only the first 20 (or so) characters can be seen and the user must use the arrows keys to get to the part of the text they wish to change.  Is this a setting somewhere?

    For the <htmlb:inputField> look at attributes maxlength, size and width.
    <b>width:</b> Determines the text width for the input field. We recommend that you use the size attribute instead of width.
    <b>size:</b> Determines the size of the input field.
    <b>maxLength:</b> Maximum length of the user input.
    I must admit that this documentation is not tell me enough. Will ask on Monday about this.
    As for your remark "works differently when viewed through Portal": You keep in mind that once a BSP application is running with the portal, all stylesheets (*.CSS) files are loaded from the portal server, and not the webAS.
    Now it could happen that you are running an EP and an older (or incompatible) patch level than your BSP stylesheets are at the moment. For EP6, starting from what I remember at SP11, there is planned a technique to install the latest stylesheets from service market place. You ask about this via OSS, queue EP-PIN-?-STY (something like this).

  • HT5622 my apple id is not working when i sign in from my laptop it works but when i sign in from my iphone4 then its not working it gives the message of "your aapleid or password is incorrect"? how can i solve this problem please help

    my apple id is not working when i sign in from my laptop it works but when i sign in from my iphone4 then its not working it gives the message of "your aapleid or password is incorrect"? how can i solve this problem please help

    Hey nocillado,
    Thanks for using Apple Support Communities.
    It sounds like you have 2 things you want to address. These articles can help you use iCloud with your existing Apple ID.
    Get help activating your iPhone
    http://support.apple.com/kb/ts3424
    Using your Apple ID for Apple services
    http://support.apple.com/kb/ht4895
    Using the same Apple ID for Store purchases and iCloud (recommended)
    Have a nice day,
    Mario

  • TS1630 My Iphone 4s reciever is not working properly, when i call someone from my iphone 4s.  can any one help me how to solve this problem?

    My Iphone 4s reciever is not working properly, when i call someone from my iphone 4s.  can any one help me how to solve this problem?

    You might like to define "not working properly".

  • Event IDs 136 and 137 0x80000000000000 in System Log on Windows 2008 R2 Server, Exchange 2010 in Cluster

    Hi,
    I'm having an issue with one of my exchange 2010 Servers. We had a power outage and upon recovery, I cannot start Services Net.Pipe Listener Adapter and Net.Tcp Listener Adapter (And thus cannot Start IIS and provide Exchange Client Services.) This is a
    physical server (Not VMWare or Hyper-V)
    The System event log has lots of Event 136's and 137s on Ntfs with the keyword - 0x80000000000000 - The General Messages are: The default transaction resource manager on volume C: encountered an error while starting and its metadata was
    reset.  The data contains the error code.
    and
    The default transaction resource manager on volume OS encountered a non-retryable error and could not start.  The data contains the error code.
    XML Output as follows:
    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
      <Provider Name="Ntfs" />
      <EventID Qualifiers="32772">136</EventID>
      <Level>3</Level>
      <Task>2</Task>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-17T18:10:37.788942300Z" />
      <EventRecordID>315532</EventRecordID>
      <Channel>System</Channel>
      <Computer>server.domain.com</Computer>
      <Security />
      </System>
    - <EventData>
      <Data />
      <Data>C:</Data>
      <Binary>1C00040002003000020000008800048000000000060019C000000000000000000000000000000000060019C0</Binary>
      </EventData>
     </Event>
    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
      <Provider Name="Ntfs" />
      <EventID Qualifiers="49156">137</EventID>
      <Level>2</Level>
      <Task>2</Task>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-17T18:10:37.788942300Z" />
      <EventRecordID>315531</EventRecordID>
      <Channel>System</Channel>
      <Computer>server.domain.com</Computer>
      <Security />
      </System>
    - <EventData>
      <Data />
      <Data>OS</Data>
      <Binary>1C0004000200300002000000890004C000000000020100C000000000000000000000000000000000020100C0</Binary>
      </EventData>
      </Event>
    When I attempt to start the services - I get the following errors:
    The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error: 
    Transaction support within the specified resource manager is not started or was shut down due to an error.
    The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error: 
    Transaction support within the specified resource manager is not started or was shut down due to an error.
    I have tried the "fsutil resource setautoreset true" fix without success.
    Any ideas or direction would be much appreciated. Restoring this server will be extremely difficult.
    Thanks!

    We can close this question.
    From an elevated prompt, I ran 'fsutil resource setautoreset true' and attempted to remove the files with .blf and regtrans-ms file extensions from C:\Windows\System32\config\TxR. but these files were locked by system processes. (They are also
    tagged with the hidden file attrib so you may not see them at first)
    So, I booted the system with a Windows 2008 R2 Install Disk, selected repair OS and selected the command prompt. I then performed a chkdsk /f c: and selected "Y" to unmount the drive. It made some repairs.
    With the system booted from the install disk, and chkdsk executed, the locks were freed and I was able to delete the files from C:\Windows\System32\config\TxR.
    Once the system rebooted, the services came back fine and everything was back to normal.

  • Record the CPU Load in a log for Windows 2008 R2

    Use performance monitor and log it to a file.

    Hi,
    I am an Oracle DBA. I need to record the load of the CPU for windows 2008 R2. Load in the sense Total Memory, Available Memory, Cached and Free. All together into a log.
     Kindly suggest me on the same.
    Thank you.
    This topic first appeared in the Spiceworks Community

  • Jar works different when executed with webstart

    Hello, I have a problem when executing an app with webstart. When I execute the jar directly on windows everything works fine, but when I execute the webstart link it executes but not correctly. The application has some timers that don't work. The rest of the application seems to be ok. Anyone has a clue about this problem? Thanks

    Hello, I have a problem when executing an app ...What application? What does it do? Do you control
    the source code?
    ..with webstart. What is the URL the the JNLP? Or failing that,
    what is the JNLP content?
    Is there any stacktrace in the Java console?
    Do you have the console pop-up for web start apps.?
    ...When I execute the jar directly on windows
    everything works fine, but when I execute the
    webstart link it executes but not correctly. The
    application has some timers that don't work. Timers don't work? Maybe they are just lazy!
    Or to put that another way, what is supposed
    to happen at the end of the time that does not
    happen in the web start app.? Are exception
    or error stacktraces printed to the console?
    ...The rest
    of the application seems to be ok. Anyone has a clue
    about this problem? Without answers to the questions above,
    we are really just guessing.
    Message was edited by:
    AndrewThompson64

  • Oracle 11g on CITRIX ( windows 2008 R2 ) OS batch file call fails

    Hello Sir/Madam,
    I've been using HOST built-in to invoke a command window to call another application from my oracle application form. The application is GFS Forms 6i on Oracle 11g db w/ XP OS. This logic works.
    --XP OS logic:
    declare
    cmd varchar2(200);
    url varchar2(200) := 'C:\PROGRA~1\ADVANT~1\GFS\start_grids_with_coords_pd.bat';
    location1 varchar2(100);
    location2 varchar2(100);
         begin
              go_block('GAS_SERVICES');
         location1 := substr(:gas_services.location_coord, 1, 5);
         location2 := substr(:gas_services.location_coord, 6, 5);
              tool_env.getvar('comspec', cmd);
         host('cmd /c start '||url ||' '||location1||' '||location2);
         end;
    Now, we are upgrading to W7 OS also, we would like use this function on CITRIX ( Windows server 2008 R2 ) server. For some reason, we are encountering errors when tilda /( squiggly ) line is used or a double quote
    -- CITRIX/W7 logic:
    declare
    cmd varchar2(200);
    url varchar2(200) := 'C:\PROGRA~2\ADVANT~1\GFS\start_grids_with_coords_pd.bat';
    location1 varchar2(100);
    location2 varchar2(100);
         begin
    go_block('GAS_SERVICES');
         location1 := substr(:gas_services.location_coord, 1, 5);
         location2 := substr(:gas_services.location_coord, 6, 5);
    tool_env.getvar('comspec', cmd);
         host('cmd /c start '||url ||' '||location1||' '||location2);
         end;
    I'll appreciate your help!
    Regards,
    Vani Sonti
    Edited by: user11141511 on May 21, 2013 1:46 PM

    Hello,
    Have you tried using long filename instead of short filename ? When using long filename, you need to enclose it with double quotes.
    Exemple :
    url varchar2(200) := 'C:\PROGRA~1\ADVANT~1\GFS\start_grids_with_coords_pd.bat';
    become
    url varchar2(200) := 'C:\PROGRAM FILES\ADVANT_WHATEVER HERE\GFS\start_grids_with_coords_pd.bat';
    and
    host('cmd /c start '||url ||' '||location1||' '||location2);
    become
    host('cmd /c start '|| chr(34) || url || chr(34) || ' '||location1||' '||location2);
    This work fines with Forms 6i on Windows 2003 and Citrix, but didn't try on Windows 2008.

  • SWF animations not working properly when exported as PDF from InDesign

    I'm using InDesign CS5 and have created a document that I want to add interactivity and animations to. I've created buttons and page destionations, etc, which all work perfectly  when exported to a PDF but the simple animation that I wanted to include don't work. The animations have been created in InDesign then selection exported as a SWF file and then imported and placed in InDesign and then exported as an interactive PDF where the animations either don't work, haven't been picked up or don not work as they should. What am I doing wrong, how do I get the animations to work correctly?

    Try this tutorial:
    http://tv.adobe.com/watch/csinsider-design/indesign-creating-interactive-pdfs-with-page-tu rn-and-flash-animations/

  • Error using jar, but the programme works right when i run it from any IDE

    I have a programme with 25 .java archives. Is a GUI with a main panel and a JToolBar. When i run ir from Eclipse iDE, NetBeans or in the Linux shell it works rigth. Then i try to make a .jar. In the process i haven't any error, and when the application starts either. But when i click in some of the JMenuItems, they don't work. The function of this Items are change the main panel. It's like some .class of event listeners aren't included, but i check the .jar and has the same .class archives than the compiled project.
    What can be problem?? It's very urgent, please.
    Regards

    I'm so sorry for annoying you, i'm a poor stupid
    student that don't have money to hire an expert, so i
    try to learn and find help everywhere. But, don't
    worry, i resolve my problem by myself.what errors are you getting. It would be helpful if you could post the errors or some stack traces that you are getting

  • Task doesn't run when "Start in" contains a UNC path

    We have a central scripts repository on a servershare \\fileserver\scripts$. That directory also contains all the functions and libraries we use in our scripts. On Windows 2008 (R2) this has always worked as a charm. But now we have our first Windows Server
    2012, and now it doesn't work.
    We get 2 errors:
    Event ID: 101
    Task Scheduler failed to start "\Simpel test" task for user "Domain\Serviceaccount". Additional Data: Error Value: 2147942667.
    Event ID: 203
    Task Scheduler failed to launch action "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" in instance "{6e09d300-4d0e-4e13-80de-d7091384e939}" of task "\Simpel test". Additional Data: Error Value: 2147942667.
    When I search for this error, I find numerous hits that the path on "Start in" shouldn't contain quotes "". But we don't have quotes in that line, it's just \\fileserver\scripts$. When I run the script from the command line, it workes
    like a charm, so it has nothing to do with rights. I've also tried the FQDN, and added it to the Trusted Sites.
    If tried everything to my knowledge, and the only times it works, is when I don't use a UNC path but a local path or no path at all. But then the script fails because it can't access the functions and libraries.
    I hope someone has a solution.

    Hi,
    Regarding the current issue, I suggest you could try to refer to the following similar thread to see if it could help.
    running a scheduled task in windows 2008 r2
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/6f830896-2370-49db-924a-6caf87deaf6e/running-a-scheduled-task-in-windows-2008-r2?forum=winservergen
    In addition, I suggest we could try to disable UAC and reboot the server to see if the issue persists.
    Hope this helps.
    Best Regards,
    Andy Qi
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Adobe Reader 11 Bootstrap method doesn't work from UNC path

    Hello,
    I am trying to incorporate Adobe Reader 11 for Windows as an unattended installation in a script, the same way I have Reader 10 setup using the bootstrapper installation method.
    I have extracted the Reader 11 Setup executable using 7-zip after "unblocking" the file in its properties, used the Customization Wizard 11 to tweak a few options, and updated the Setup.ini accordingly (including the transform and the unattended install parameters).
    Everything works great when I have the files on my desktop. When I copy the folder up to the server share where it will reside, I get an error when trying to run the setup.exe (not even using a script yet).
    The error:
    "This installation package could not be opened. Verify that the package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer package."
    I have verified all the permissions, tried everything multiple times, tried using the Customization Wizard with the files on the server, and nother has worked. I have done this with Adobe Reader 10 including using the method of chaining updates in the Setup.ini quite well.
    Any suggestions for things I might try?
    Thanks!

    Solved.
    Apparently the problem lies with the machine I was trying the install on. I copied my fully configured bootstrap deployment back to the server and tested it out on a VM and another computer. It worked just fine there. I have no idea why it worked locally but broke on the server for my first test machine. What a waste of the day.

  • Problem in Font when file is downloaded from query output

    Hi,
    We are facing a problem as we are not able to simulate a scenario at our end where a file is downloaded from a query. The snapshot of the file which is downloaded in excel is shown below. The name displayed below has special characters in it. The actual value for the name is VÁRADI GÁBORNÉ, but when the file is downloaded into excel, the special characters get converted to some different characters and the last character ie É gets converted to “?” and the values for the next column get concatenated to the Name 1 column and all the values move one column left.
    Sold to     Cl     Name 1                                      Sal.per.     Sales doc.
    57983     CD     V&#32629;ADI G&#32603;ORN?00002110       2150451     
    57983     CD     V&#32629;ADI G&#32603;ORN?00002110       2150451     
    The procedure used by the user to download the file from the query is as follows:
    1.     The query is executed in background with file name entered in Save with ID option
    2.     After the job is complete, the file is displayed from the saved list of that query.
    3.     This saved list is then downloaded as .DAT file and then opened with excel.
    Any pointers to solve the problem will be highly appreciated.
    Regards,
    Kaushal Mehta

    Hi,
    There is no problem of device type as when we are testing the query with the same inputs (same variant, same printer), the output to the excel comes correctly. But at the user end, the output does not come out properly. Infact the saved list displayed for that query shows the output to be correct, but when that list is exported to excel, the output gets distorted for the user (not for us).
    Thanks for your inputs,
    Kaushal

  • How to Recover Windows 2008 R2 OS when there is no IMAGE is available ?

    I am using Windows Server 2008 R2 Standard SP1 OS in my Dell PowerEdge 2950 hardware.
    I was doing DCOM settings. I was adding new User group and permission for the newly added user group. After completion of this activity I re-booted my Machine. After re-boot, CTRL + ALT + Delete to unlock this computer appeared on the screen. 
    As soon as I hit Alt +Ctrl+Delete key, a screen turns to BLACK. During this time I checked the VGA Signal availability to Monitor and it is there. HDD activity is also exist (LED indication).
    Then I re-boot the machine and chosen Safe Mode and the case is remain same.
    I don't have my C Drive Image to recover (Acronics).
    I don't understand show do I recover/repair Windows ....
    Someone Pls reply if any solution is exist.
    Regards
    Debashish
    Bangalore.     

    Thanks, for quick reply.
    I had tried "Last known good" but did not work.
    Remote Login did not came to my mind. Other then this option I tried with all the respect but no positive result. Finally I started from the scratch loading OS.
    I was thinking to take an Acronics image before doing DCOM settings. But I was sure that nothing will go wrong as I was just adding new user group. Don't know what has happed to the system.
    Last 2 days it was very bad time for me.
    Anyway thanks a lot for your support.
    Regards, Debashish.

Maybe you are looking for