Windows logs event – file accessed from within server or outside server?

  audit-logging, event-log, windows

I have a file that is getting automatically updated everyday. In order to find the source of update, I setup auditing on the file and got the event corresponding to the update. But unfortunately I couldn’t understand the event log.

I just want to find if the source of update is from within the server or from outside the server?

All I could see there is name of the account that is used to modify the file.

Any guidance or pointing in right direction would be helpful. I am more than happy to research and find answer but I dont know what to research for. I googled over this for hours but couldnt find anything. I guess I am searching in wrong area.

Source: Windows Questions

LEAVE A COMMENT