Windows Server Event: 4663

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

System Event » Windows Server Event: 4663

Event ID 4663: Object access attempt.

Description This is a Data ONTAP event. An object(file or directory) has access attempt has been made. The access could be to
  • Read object
  • Write object
  • Get object attributes
  • Set object attributes
Category File access

Information:

For this event, Data ONTAP audits only the first SMB read and first SMB write operation (success or failure) on an object. This prevents Data ONTAP from creating excessive log entries when a single client opens an object and performs many successive read or write operations to the same object.

Pro tip:

  • ADAudit Plus offers in built reports that collect logs in real time and presents it to the administrator whenever an attempt has been made to access an object.
  • The reports provide details about the object that is being accessed, who attempted the access and when the action was performed.

Event 4663 applies to the following operating systems:

  • Windows Server 2008 R2 and 7
  • Windows Server 2012 R2 and 8.1
  • Windows Server 2016 and 10

Corresponding event in Windows Server 2003 and earlier versions - 567.