SharePoint Audit Log Event ID 55

SourceSharePoint (LOGbinder SP)
Audit FlagUnknown or not applicable
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

55: Site collection information management policy changed

This is an event from SharePoint audit event from LOGbinder SP generated by Audit Flag  Unknown or not applicable.

On this page

The site collection informataion management policy configuration is found on the Site CollectionAdministration>Policies page in SharePoint. Event ID 43 (document updated) can be correlated to this event with the Policy ID.

The collection set (information management policy) that governs content has changed. Expiration, auditing, document labels, and bar codes are examples of content management. This event is always audited and not connected with any audit flag.

The data shows the detail of the policy after it was changed. The previous configuration is not shown.

Free Security Log Resources by Randy

Description Fields in 55

  • Occurred: this is the date and time when SharePoint recorded the event to the internal SharePoint audit log and may be earlier than the date/time in the header of this event which reflects when LOGbinder SP wrote the event to Windows event log
  • Site: This is the URL of the site generating this event
  • User: name of the user who performed the action
  • Policy details: this data shows additional information about the policy

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 55

Site collection information management policy changed
Occurred: 12/6/2011 3:23:02 AM
Site: http://sp2010-sp
User: Randy F. Smith
Policy details: <data><p:Policy xmlns:p="office.server.policy" local="false" id="ba091f4a-b41f-4748-93f1-6d9a310f7ffe"><p:Name>TestPolicy</p:Name><p:Description>this is the description</p:Description><p:Statement>this is the statement</p:Statement><p:PolicyItems><p:PolicyItem featureId="Microsoft.Office.RecordsManagement.PolicyFeatures.PolicyAudit" UniqueId="16076acb-9910-46eb-a5ca-c7ddfe5fb2ee"><p:Name>Auditing</p:Name><p:Description>Audits user actions on documents and list items to the Audit Log.</p:Description><p:CustomData><Audit><View /></Audit></p:CustomData></p:PolicyItem></p:PolicyItems></p:Policy></data>

 

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!