Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > Filemon
  New Posts New Posts RSS Feed: Security Event Logs being cleared by User=SYSTEM
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Security Event Logs being cleared by User=SYSTEM

 Post Reply Post Reply
Author
Message
  Topic Search Topic Search  Topic Options Topic Options
acuster View Drop Down
Newbie
Newbie


Joined: 18 August 2006
Online Status: Offline
Posts: 2
  Quote acuster Quote  Post ReplyReply Direct Link To This Post Topic: Security Event Logs being cleared by User=SYSTEM
    Posted: 07 November 2009 at 2:35am
OK, I am dumbfounded on this one.  
Our Security event logs are being cleared.  This is a serious violation of 
out ITRM policy for obvious reasons.  The event log states USER=system.  
Clearing always occurs  at the top of the hour.  This behavior is indicative 
of a script or EXE.  All the obvious have been checked; GPO and scheduled 
tasks.  We have checked the other logs, and nothing occurs around the same 
time. The SA team is thinking it is an application proc doing this, but I 
need definitive proof of the root cause.
Is there any other logs, or auditing that will show what proc, running under 
the system context, is clearing the security log?  Or does anyone know of a 
free app that has more granular auditing. 
I am hoping this community can help me before I open a case with MS

Thanks In Advance
Aaron
Aaron
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Privacy Statement