Windows Event log code
We do auditing on specific folders on windows 2003 servers.
I need to make alert on a file creation or modification on these folders.
It is hard to know when a file is create or modify. It is the same windows event number 560
I notice that, in arcsight, the device custom sting 1 refer to Accesses in the windows event log and have numbers like %%1538%%1541%%etc.......
Does somebody know what means theses numbers ?
Does a table conversion exist to tell example %%1538 = READ CONTROL
%%1537 = DELETE
Or somebody has a working solution to track a modification and a creation of a file
Thanks in advance
Gents, Am I missing something? I'm running WUC 22.214.171.12480.0 and Device Custom String 1 for both a file create event and file write event looks like
READ_CONTROL|ReadData (or ListDirectory)|WriteData (or AddFile)|AppendData (or AddSubdirectory or CreatePipeInstance)|ReadEA|WriteEA|ReadAttributes|WriteAttributes
The only difference is the write event has an associated (via File ID) open event and the file create has no associated 560 event. Actually when testing I did another file write and the open/write events had different File ID's, but I don't want to go there for now. One fubar at a time...
Thanks in advance for your assistance.
Can you let me know if you are using one WUC to collect all your windows logs for windows 2003, windows 2008 and windows Domain Active Directory logs or do you actually separate them into different connectors? Like you said in once of your earlier post, I am also using the Domain connector to collect file/folder audit logs on windows 2003 servers and a WUC to collect windows 2008 servers logs. Did you consolidate your domain collector hosts into the WUC connector? Thanks.
I am currently using separate WUCs to collect from Win2003 vs Win2008, but that was just to distribute the load equally. As far as I know you can have any combination of Win2003/2008/Local/DC logs on a single WUC.
The problem appear again, install version 126.96.36.19927 of WUC and %%code appear again in the Device Custom String 1 for Windows server 2003, 2008 and 2012 ?????????
Do you have the same problem too ?
Thanks in advance
Will open a ticket to Arcsigh