Windows Security Log Event ID 517
Operating Systems |
Windows Server 2000
Windows 2003 and XP
|
Category | System |
Type
|
Success
|
Corresponding events
in Windows
2008 and Vista |
1102
|
517: The audit log was cleared
On this page
Event 517 is logged whenever the Security log is cleared, REGARDLESS of the status of the Audit System Events audit policy.
The Primary User Name and Client User Name fields will identify the user who cleared the log. Primary User Name will correspond to the system, and Client user name will indicate the user who cleared the log.
Free Security Log Resources by Randy
- Primary User Name: The username of the system where the log was cleared (always SYSTEM)
- Primary Domain: Since this takes place within the system, domain is NT Authority
- Primary Logon ID: Logon ID of the computer
- Client User Name: The user that cleared the audit log
- Client Domain: The domain of the user that cleared the log
- Client Logon ID: Logon ID of the user that cleared the log. If the log was archived the logon ID can be used to correlate to logon event ID 528 or 540.
Setup PowerShell Audit Log Forwarding in 4 Minutes