I am seeing the following event in the security log for all of our Win2k3
servers. We use a security template to configure items like auditing events,
user rights, etc.. I am not seeing the event in the Win2k servers. Any help
would be appreciated.



Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 1/31/2005
Time: 9:21:01 AM
User: NT AUTHORITY\LOCAL SERVICE
Computer: <ServerName>
Description:
Object Open:
Object Server: Security
Object Type: File
Object Name: \Device\NetbiosSmb
Handle ID: -
Operation ID: {0,20574410}
Process ID: 900
Image File Name: C:\WINDOWS\system32\svchost.exe
Primary User Name: LOCAL SERVICE
Primary Domain: NT AUTHORITY
Primary Logon ID: (0x0,0x3E5)
Client User Name: -
Client Domain: -
Client Logon ID: -
Accesses: SYNCHRONIZE
ReadData (or ListDirectory)
WriteData (or AddFile)

Privileges: -
Restricted Sid Count: 0
Access Mask: 0x100003

Thanks,

Brian Cohen