Auditing events 4656 and 4658 on Windows folder on Server 2008
Posted
by PCurd
on Server Fault
See other posts from Server Fault
or by PCurd
Published on 2009-07-22T13:24:35Z
Indexed on
2010/03/20
22:01 UTC
Read the original article
Hit count: 568
During an overnight system state backup we are seeing thousands of success audit events (4656, 4658) on the folder c:\windows\servicing, system32 and others in the windows folder.
We use file success auditing on some files so I can't disable it but this deluge is filling up the logs and making reporting tricky.
What is the harm of changing the auditing settings on the windows folder?
What are the recommended settings to put on the files for those people doing system state backups?
Thanks,
© Server Fault or respective owner