Page tree

PATROL generates the following events in the Windows security event log:

  • Event ID 560 - Object Open
  • Event ID 562 - Handle Closed

Explanation

Solution

PATROL generates these events during normal data collection if success auditing is enabled for object access.

To prevent PATROL from generating these events, you can turn off success auditing for object access.

This setting determines whether to audit user access to an object.

An object could be a file, folder, registry key, printer, or other system object. For more information, see Microsoft KB article 149401.

  • No labels