 Windows Security Log Event ID 5140
        Windows Security Log Event ID 5140
        
        
        
         
        
    
    
    
        
	
		| Operating Systems | Windows 2008 R2 and 7 Windows 2012 R2 and 8.1
 Windows 2016 and 10
 Windows Server 2019 and 2022
 
 | 
		| Category • Subcategory
 | Object Access • File Share
 | 
		| Type | Success 
 | 
		| Corresponding events in Windows
                    2003
 and before
 |  | 
     
    
        5140: A network share object was accessed
    
    
    
        On this page
    
    
    Windows logs this event the first time you access a given network share during a given logon session.  Be aware that Windows Server 2008 logs off network logon sessions even sooner than past versions of Windows.  When a user closes all open files on a server it seems to immediatelly log him off.
Free Security Log Resources by Randy 
    
    
        
                    Subject:
The user and logon session that accessed the share.
    - Security ID:  The SID of the account.
- Account Name: The account logon name.
- Account Domain: The domain or - in the case of local accounts - computer name.
- Logon ID is a semi-unique (unique between reboots) number that identifies the logon session.  Logon ID allows you to correlate backwards to the logon event (4624) as well as with other events logged during the same logon session.
Network Information:
    -  Source Address:  IP Address of the client computer where the user initiated the access
-  Source Port:  source TCP port of the connection - not useful
Share Name:   
The name of the share. 
    - to find out what folder or printer the share corresponds to, use Computer Manager\Shares
                Supercharger Free Edition 
                 
                
                Supercharger's built-in Xpath filters leave the noise behind. 
                Free.