SharePoint Audit Log Event ID 35

SourceSharePoint (LOGbinder SP)
Audit FlagSecurityChange
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

35: Permission level deleted

This is an event from SharePoint audit event from LOGbinder SP generated by Audit Flag  SecurityChange.

On this page

A permission level or "role" was deleted. Permission levels are determined at Site Collection Administration. If a permission level is deleted all groups that are assigned that level will no longer have that access.

Free Security Log Resources by Randy

Description Fields in 35

  • Occurred: this is the date and time when SharePoint recorded the event to the internal SharePoint audit log and may be earlier than the date/time in the header of this event which reflects when LOGbinder SP wrote the event to Windows event log
  • Site: This is the URL of the site generating this event
  • User: name of the user who performed the action
  • Object
    • Type:
    • URL: URL of the object targeted by this operation
    • Title: title of the object targeted by this operation
    • Description: discription of the object that appears on the page
  • Permission Level Details:
    • ID: internal to SharePoint

Supercharger Free Edition


Your entire Windows Event Collection environment on a single pane of glass.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 35

Permission level deleted
Occurred: 11/22/2011 1:04:19 AM
Site: http://sp2010-sp
User: System Account
Object
  Type: Web
  URL: http://sp2010-sp
  Title: SP2010
  Description: ddddddddddddddddddd
Permission Level Details
  ID: 1073741930
The permission level name is not available because Microsoft does not report this. Refer to events 34 or 36, as these may contain the name.
 

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources