Auditing events 4656 and 4658 on Windows folder on Server 2008

Posted by PCurd on Server Fault See other posts from Server Fault or by PCurd
Published on 2009-07-22T13:24:35Z Indexed on 2010/03/20 22:01 UTC
Read the original article Hit count: 573

During an overnight system state backup we are seeing thousands of success audit events (4656, 4658) on the folder c:\windows\servicing, system32 and others in the windows folder.

We use file success auditing on some files so I can't disable it but this deluge is filling up the logs and making reporting tricky.

What is the harm of changing the auditing settings on the windows folder?

What are the recommended settings to put on the files for those people doing system state backups?

Thanks,

© Server Fault or respective owner

Related posts about windows-server-2008

Related posts about audit