517: The audit log was cleared
On this page
Event 517 is logged whenever the Security log is cleared, REGARDLESS of the status of the Audit System Events audit policy. The Primary User Name and Client User Name fields will identify the user who cleared the log. Primary User Name will correspond to the system, and Client user name will indicate the user who cleared the log.
The audit log was cleared Primary User Name: SYSTEM Primary Domain: NT AUTHORITY Primary Logon ID: (0x0,0x3E7) Client User Name: Administrator Client Domain: ACME Client Logon ID: (0x0,0x3F5C9)
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection
Go To Event ID:
Security Log Quick Reference Chart Download now!