Event ID 5140
A network share object was accessedA network share object was accessed. Subject: Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Network Information: Object Type: %5 Source Address: %6 Source Port: %7 Share Name: %8 Share Path: %9 Access Request Information: Access Mask: %10 Accesses: %11
Auditing:
Conditional
Volume:
Low
Medium
Logged the first time a network share is accessed during a logon session.
Microsoft Documentation
Name | Field | Insertion String | OS | Example | ||
---|---|---|---|---|---|---|
Security ID | SubjectUserSid | %1 | Any | DOMAIN\theuser | ||
Account Name | SubjectUserName | %2 | Any | theuser | ||
Account Domain | SubjectDomainName | %3 | Any | DOMAIN | ||
Logon ID | SubjectLogonId | %4 | Any | 0x541f98 | ||
Object Type | ObjectType | %5 | Any | File | ||
Source Address | IpAddress | %6 | Any | 10.23.44.12 | ||
Source Port | IpPort | %7 | Any | 40215 | ||
Share Name | ShareName | %8 | Any | \\*\Documents | ||
Share Path | ShareLocalPath | %9 | Any | \??\C:\Documents | ||
Access Mask | AccessMask | %10 | Any | 0x1 | ||
Access List | AccessList | %11 | Any | View Codes |
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"File Share"
Operating Systems:
Windows Vista Windows 2008 Windows 7 Windows 2008 R2 Windows 8 Windows 2012 Windows 8.1 Windows 2012 R2 Windows 10 Windows 2016 Windows 2019 Windows 11 Windows 2022Tags:
Audit Success Audit FailureCorrelated Events:
4624LEFT/RIGHT arrow keys for navigation
Back to List