Windows Security Log Event ID 517
Operating Systems Windows Server 2000
Windows XP
Windows Server 2003
CategorySystem
Type Success
Corresponding events
in Windows 2008
and Vista
1102  
Discussions on Event ID 517
Ask a question about this event

517: The audit log was cleared

On this page

Event 517 is logged whenever the Security log is cleared, REGARDLESS of the status of the Audit System Events audit policy.

The Primary User Name and Client User Name fields will identify the user who cleared the log. Primary User Name will correspond to the system, and Client user name will indicate the user who cleared the log.

  • Primary User Name: The username of the system where the log was cleared (always SYSTEM)
  • Primary Domain: Since this takes place within the system, domain is NT Authority
  • Primary Logon ID: Logon ID of the computer  
  • Client User Name: The user that cleared the audit log 
  • Client Domain: The domain of the user that cleared the log
  • Client Logon ID: Logon ID of the user that cleared the log. If the log was archived the logon ID can be used to correlate to logon event ID 528 or 540.

Top 10 Windows Security Events to Monitor

The audit log was cleared
  Primary User Name: SYSTEM
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: Administrator
  Client Domain: ACME
  Client Logon ID: (0x0,0x3F5C9)

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this



Training for the Windows Security Log