Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

4656 event log with FIM on windows 7 machine filter

$
0
0

I get the event below from a windows 7 workstaion frequently. Thoughts?

 

Event FieldInformation
OperationTypeObjectOpenFailure
AccessPropertiesMask: -
ServingProcess{0x314,0}
OperationID{00000000-0000-0000-0000-000000000000}
ObjectHandleID0x0
ObjectNamePlugPlaySecurityObject
ObjectTypeSecurity
ObjectServerPlugPlayManager
PrivilegesExercised0x2
AccessRequestedUnknown specific access (bit 1)
DestinationLogonID
DestinationDomain
DestinationAccount
SourceLogonID0x2cebe
SourceDomainBBBBBBB
SourceAccountZZZZZZZ
ExtraneousInfo
ProviderSIDMicrosoft-Windows-Security-Auditing 4656
InferenceRule
ToolAliasVista Security
Severity3
DetectionTime12:50:08 Thu Apr 28 2016
InsertionTime12:50:09 Thu Apr 28 2016
DetectionIPXXXXXX.i.fmedr.com
ManagerYYYYYYY
InsertionIPXXXXXX.i.fmedr.com
EventInfoObject open failed "PlugPlayManager (Security) PlugPlaySecurityObject"
Event NameObjectAuditFailure

Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>