System Event » Windows Server Event: 5143
Event ID 5143: A network share object was modified.
Description | This event is generated each time a network share object is modified. |
Category | Object access |
Subcategory | File share |
This event logs the following information:
Subject |
|
Share information |
|
Reasons to monitor this event:
- This event is significant if you have high-value computers for which you need to monitor all modifications to all shares.
- Specific shares can also be monitored using this event ("Share name").For example, you could monitor all changes to the SYSVOL share on domain controllers
Pro tips:
- ADAudit Plus offers reports that collect logs in real time and presents it to the administrator whenever any network share object has been modified.
- The reports provide details about the network share object that has been modified, who modified it and when the action was performed.
Event 5143 applies to the following operating systems:
- Windows Server 2008 R2 and 7
- Windows Server 2012 R2 and 8.1
- Windows Server 2016 and 10
Explore Active Directory auditing and reporting with ADAudit Plus.
Account Management Auditing
Active Directory Auditing
Windows Server Auditing
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools