Event Details
User Activity->Object Access->File System Object Access->Windows 2008->EventID 5143 - A network share object was modified.
EventID 5143 - A network share object was modified.
 Sample:
A network share object was modified.
	
Subject:
	Security ID:		ITSS\igor.ilyin
	Account Name:		igor.ilyin
	Account Domain:		ITSS
	Logon ID:		0x2f253

Share Information:
	Object Type:		Directory
	Share Name:		\\*\InTrust_Reports
	Share Path:		C:\Users\Public\Documents\Dell\Reports
	Old Remark:		N/A
	New Remark:		N/A
	Old MaxUsers:		0xffffffff
	New Maxusers:		0xffffffff
	Old ShareFlags:		0x0
	New ShareFlags:		0x0
	Old SD:			
	New SD:			O:BAG:S-1-5-21-3701821694-4228108427-4157987367-513D:(A;OICI;FA;;;S-1-5-21-3701821694-4228108427-4157987367-1603)(A;OICI;0x1201bf;;;S-1-5-21-3701821694-4228108427-4157987367-1602)(A;OICI;0x1200a9;;;S-1-5-21-3701821694-4228108427-4157987367-1104)
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Object Access
Source Microsoft-Windows-Security-Auditing
TaskCategory File Share
EventId 5143
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. - 1/1/2000
Who Account or user name under which the activity occured. Subject: Account Name DCC1$
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Network Share Object Modified" Network Share Object Modified
Where The name of the workstation/server where the activity was logged. - 10.10.10.10
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. - High
WhoDomain Subject: Account Domain LOGISTICS
WhereDomain -
Result Successful or Failed -
Object Name Object Name \\*\InTrust_Reports
Object Type Share Information: Object Type Directory
Whom -
Comments
You must be logged in to comment