Checking SharePoint 2019 logs for security risks

Steve 66 Reputation points
2020-11-16T04:24:32.483+00:00

We are using SharePoint 2019 on-prem and occasionally we see communication from port 443 of the servers running SharePoint 2019 to outbound ports 6667 of some IP addresses which we don't know. Our firewall alerts us as port 6667 is used for Internet Relay Chat(IRC) applications.

The website hosted using SharePoint 2019 is open on the Internet to external customers. It is behind Cisco and web application firewalls

I check the IP addresses and if they are on a blacklist of Cisco Talos, we block the IP address.

  1. What are some other ways to check SharePoint 2019 logs for security risks?
  2. Is there in-built logging in SharePoint 2019 which can be monitored for security risks?
SharePoint Server Management
SharePoint Server Management
SharePoint Server: A family of Microsoft on-premises document management and storage systems.Management: The act or process of organizing, handling, directing or controlling something.
2,934 questions
{count} votes

Accepted answer
  1. Allen Xu_MSFT 13,821 Reputation points
    2020-11-16T09:53:12.127+00:00

    Hi @Steve ,

    SharePoint provides diagnostic logging services to debug and isolate the issues within the farm. If you want to monitor built-in logs in SharePoint 2019, please go to Central Administration -> Monitoring -> Configure diagnostic logging -> Scroll down to Trace Log section:
    40039-1-1.png

    Once logging has been in place, it will create the log files in real time, depending upon the severity of the events. We can go to the log location and find the recently updated log file to work on an existing issue in the farm.

    You can use PowerShell to work with it, please refer to this article: View diagnostic logs in SharePoint Server

    Also, It is recommended to use ULS Viewer to work with it, please refer to this article: Using ULS Viewer to Monitor and Filter SharePoint 2013 Logs

    I hope this information has been useful, please let me know if you still need assistance.


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Sharath Kumar Aluri 3,071 Reputation points
    2020-11-16T05:19:31.65+00:00

    Default location for the SharePoint Logs is "C:\program file\Common Files\Microsoft Shared\Web Server Extensions\16\LOGS"

    See the logs in the Event Viewer on your SharePoint Server's. open run and enter Evnetvwr and hit enter and then expand Windows > Application.

    Thanks & Regards,

    2 people found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.