Windows System Event: 517

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

System Event » Windows System Event: 517

Event ID 517 - The audit log was cleared.

Description The event is logged whenever the audit log is cleared, regardless of the status of the Audit System Events audit policy.
Category System

The event logs the following information:

Primary user name The username of the system where the log was cleared (always SYSTEM).
Primary domain Domain in which the audit occurred (always NT Authority)
Primary logon ID Logon ID of the computer.
Client user name The user name of the user who cleared the audit log.
Client domain The domain to which the client user belongs to.
Client logon ID Logon ID of the user that cleared the log. If the log was archived the logon ID can be used to correlate to logon event ID 528 or 540.

Pro tips:

  • ADAudit Plus notifies you whenever the audit log has been cleared.
  • You can view this event as a report, that includes details about who cleared the log, and when it was cleared.
  • If required, an alert can be set up to let the administrators know when an audit log has been cleared.

Event 517 applies to the following operating systems:

  • Windows server 2000
  • Windows server 2003 and XP

Corresponding event in Windows 2008 and Vista - Event 1102.