Event ID 5140
A network share object was accessedA network share object was accessed.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Network Information:
Object Type: %5
Source Address: %6
Source Port: %7
Share Name: %8
Share Path: %9
Access Request Information:
Access Mask: %10
Accesses: %11 Auditing: Conditional
Volume: LowMedium
Logged the first time a network share is accessed during a logon session.
Microsoft Documentation
| Name | Field | Insertion String | OS | Example | ||
|---|---|---|---|---|---|---|
| Security ID | SubjectUserSid | %1 | Any | DOMAIN\theuser | ||
| Account Name | SubjectUserName | %2 | Any | theuser | ||
| Account Domain | SubjectDomainName | %3 | Any | DOMAIN | ||
| Logon ID | SubjectLogonId | %4 | Any | 0x541f98 | ||
| Object Type | ObjectType | %5 | Any | File | ||
| Source Address | IpAddress | %6 | Any | 10.23.44.12 | ||
| Source Port | IpPort | %7 | Any | 40215 | ||
| Share Name | ShareName | %8 | Any | \\*\Documents | ||
| Share Path | ShareLocalPath | %9 | Any | \??\C:\Documents | ||
| Access Mask | AccessMask | %10 | Any | 0x1 | ||
| Access List | AccessList | %11 | Any | View Codes | ||
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"File Share" Operating Systems:
Windows VistaWindows 2008Windows 2008 R2Windows 7Windows 2012Windows 2012 R2Windows 8Windows 8.1Windows 10Windows 11Windows 2016Windows 2019Windows 2022Windows 2025Tags:
Audit SuccessAudit FailureCorrelated Events:
4624LEFT/RIGHT arrow keys for navigation
Back to List