SeAuditingFileEvents - NtDoc

Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
// ntifs.h

BOOLEAN SeAuditingFileEvents(
  [in] BOOLEAN              AccessGranted,
  [in] PSECURITY_DESCRIPTOR SecurityDescriptor
);

View the official Windows Driver Kit DDI reference

NtDoc

No description available.

Windows Driver Kit DDI reference (nf-ntifs-seauditingfileevents)

SeAuditingFileEvents function

Description

The SeAuditingFileEvents routine determines whether file open events are currently being audited.

Parameters

AccessGranted [in]

Set to TRUE if the access attempt was successful, FALSE otherwise.

SecurityDescriptor [in]

This parameter is ignored.

Return value

SeAuditingFileEvents returns TRUE if file open events are currently being audited, FALSE otherwise.

Remarks

For more information about security and access control, see Windows security model for driver developers and the documentation on these topics in the Windows SDK.

See also

SECURITY_DESCRIPTOR

SeAuditingFileOrGlobalEvents

SeDeleteObjectAuditAlarm

SeOpenObjectAuditAlarm

SeOpenObjectForDeleteAuditAlarm