SharePoint Audit Log Event ID 61

SourceSharePoint (LOGbinder SP)
Audit FlagCustom
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

61: Retention policy processed

This is an event from SharePoint audit event from LOGbinder SP generated by Audit Flag  Custom.

On this page

This event indicates that a policy is processed on a document, causing the action stipulated in the policy to be performed to the document.

Free Security Log Resources by Randy

Description Fields in 61

  • Occurred: this is the date and time when SharePoint recorded the event to the internal SharePoint audit log and may be earlier than the date/time in the header of this event which reflects when LOGbinder SP wrote the event to Windows event log
  • Site: This is the URL of the site generating this event
  • User: name of the user who performed the action
  • Object
    • Type: Document, Folder, Item, etc.
    • Subtype: usually n/a
    • URL: URL of the object targeted by this operation
    • Title: may be n/a
    • Description: may be n/a
  • Action: Action to be performed.

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 61

Retention policy processed
Occurred: 5/28/2011 11:00:26 PM
Site: https://arcit.sharepoint.xyz.abc.com
User: System Account
Object
   Type: Document
   URL: ABC/General Documents on Budget Documents.docx
   Title: Home
   Description: n/a
Action: Delete Previous Drafts

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!