Windows Security Log Event ID 517

Operating Systems Windows Server 2000
Windows 2003 and XP
Type Success
Corresponding events
in Windows 2008
and Vista

517: The audit log was cleared

On this page

Event 517 is logged whenever the Security log is cleared, REGARDLESS of the status of the Audit System Events audit policy.

The Primary User Name and Client User Name fields will identify the user who cleared the log. Primary User Name will correspond to the system, and Client user name will indicate the user who cleared the log.

Free Security Log Resources by Randy

Description Fields in 517

  • Primary User Name: The username of the system where the log was cleared (always SYSTEM)
  • Primary Domain: Since this takes place within the system, domain is NT Authority
  • Primary Logon ID: Logon ID of the computer  
  • Client User Name: The user that cleared the audit log 
  • Client Domain: The domain of the user that cleared the log
  • Client Logon ID: Logon ID of the user that cleared the log. If the log was archived the logon ID can be used to correlate to logon event ID 528 or 540.

Supercharger Enterprise

Load Balancing for Windows Event Collection


Examples of 517

The audit log was cleared
  Primary User Name: SYSTEM
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: Administrator
  Client Domain: ACME
  Client Logon ID: (0x0,0x3F5C9)

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources