Windows Event ID 4717 - or in general - best resources to learn Windows log files
I have a log event, Event ID 4717, Access list = SeServiceLogonRight, Caller Security ID = NT AUTHORITY\SYSTEM, Event Task Category = Authentication Policy Change, Target User = IIS APPPOOL\Shared, User Name = File Server, Windows Event Src = Microsoft-Windows-Security-Auditing.
This is a system-generated event. Why did it happen?
If I want to learn the answers to questions like this, where is the best place to research and learn? Microsoft has a ton of material available online, including 4717(S) System security access was granted to an account. (Windows 10) - Windows security | Microsoft Docs.
I understand what each piece of the event means, but I do not know the best way to learn why it happened; or the best way to see the sequence of log events in Alert Logic to see if other events can give me more insight into why this event would occur.
Thank you!
-
Official comment
Hi Eli Tomlinson - Looks like you haven't had any responses from our customer community with tips and tricks, so I have opened a ticket on your behalf. Our security experts should be able to provide some tips on researching logs and using the Alert Logic console to dig into logs and events.
Please sign in to leave a comment.
Comments
1 comment