SharePoint Audit Log Event ID 12

SourceSharePoint (LOGbinder SP)
Audit FlagSecurityChange
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

12: Audit policy changed

This is an event from SharePoint audit event from LOGbinder SP generated by Audit Flag  SecurityChange.

On this page

This event indicates audit policy has been set on a specific object.  See event ID 11 for site collection audit policy change.

Free Security Log Resources by Randy

Description Fields in 12

  • Occurred: this is the date and time when SharePoint recorded the event to the internal SharePoint audit log and may be earlier than the date/time in the header of this event which reflects when LOGbinder SP wrote the event to Windows event log
  • Site: This is the URL of the site generating this event
  • User: name of the user who performed the action
  • Object
    • Type: Document, Folder, Item, etc
    • Subtype: usually n/a
    • URL: URL of the object targeted by this operation
    • Title: may be n/a
    • Description: may be n/a
  • New audit policy: Audit Flags

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 12

Audit policy changed
Occurred: 11/21/2011 8:45:51 PM
Site: http://sp2010-sp
User: System Account
Object
  Type: Document
  Subtype: n/a
  URL: Shared Documents/FinancialReport.xlsx
  Title: n/a
  Description: n/a

New audit policy: View

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!