Event ID: 563

Object Open for Delete

Object Open for Delete:
    Object Server:     %1
    Object Type:       %2
    Object Name:       %3
    Handle ID:         %4
    Operation ID:      {%5,%6}
    Process ID:        %7
    Primary User Name: %8
    Primary Domain:    %9
    Primary Logon ID:  %10
    Client User Name:  %11
    Client Domain:     %12
    Client Logon ID:   %13
    Accesses:          %14
    Privileges:        %15
    Access Mask:       %16

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /category:"Object Access"
How to enable Windows Auditing

Audit Category:
Object Access
Corresponding Events:

LEFT/RIGHT arrow keys for navigation

Back to List