Skip to main content

The Windows Security Log Contains Multiple Events 5140 Generated by Netwrix Auditor

Symptom​

The Windows Security log of the server audited by Netwrix Auditor contains multiple events with the Event ID 5140:

5140(S, F): A network share object was accessed.

Cause​

You get these events from your Netwrix Auditor Server because during the data collection, Netwrix Auditor for File Servers or Windows Servers reads the list of shared objects which triggers events 5140.

Resolution​

This event is being generated for each attempt to access a file share within a network that is considered as normal behavior according to Microsoft.

Learn more about this event in 5140(S, F): A network share object was accessed βΈ± Microsoft: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5140