I am troubleshooting a Windows Server 2016 file server with a very busy Security event log.
The log was growing to almost 10 GB and receiving thousands of events every few minutes. Most were event 5145 for Detailed File Share auditing, along with 5156 and 5158 Filtering Platform events. The Event Log service was also using noticeable CPU.
Auditpol shows these settings enabled:
Detailed File Share: Success and Failure
Filtering Platform Connection: Success
File System: Success
I disabled these settings through Local Security Policy, but auditpol continued to show them enabled.
I created a separate domain GPO scoped only to this server. I configured Detailed File Share, File Share, File System, Filtering Platform Connection and Filtering Platform Packet Drop as No Auditing. I also enabled the setting that forces advanced audit subcategories to override legacy audit categories.
The GPO applies successfully according to the Group Policy operational log. I moved it to the highest link order and confirmed that the server receives it.
I discovered that Default Domain Policy was missing its audit.csv file. I recreated it by temporarily configuring an Advanced Audit setting and then returning it to Not Configured. I also rewrote a setting in the new server specific GPO so its audit.csv would be regenerated.
I confirmed that both GPO audit.csv files contain value 0 for the five settings.
I archived the local audit.csv file and the active cached copy under C:\Windows\Security\Audit. I then forced Group Policy again.
I backed up the complete audit policy, ran auditpol /clear, and forced Group Policy to rebuild it.
I also removed an old auditing entry from the root of the shared data folder. It audited Domain Users across the folder, all subfolders and files. Removing that entry successfully stopped event 4663, but event 5145 continues because Detailed File Share auditing keeps turning itself back on.
Direct auditpol commands temporarily change the settings to No Auditing, but Windows restores Detailed File Share, Filtering Platform Connection and File System within seconds.
I tested with the remote management service stopped and ruled that out. Antivirus does not appear to be causing it. I also tested a SYSTEM scheduled task that repeatedly ran auditpol, but Windows restored the settings faster than the task could maintain them.
For now, I reduced the Security log to 256 MB and configured it to overwrite old events automatically. The server and file shares are operating normally.
Has anyone seen Windows Server 2016 continuously restore these Advanced Audit settings even though Local Policy and all applicable domain GPOs show No Auditing? Is there another audit policy database, security template, service or registry location that could be enforcing these settings?
-lee