audit folder/file delet

From: Edy Werder (werder_at_interwatt.ch)
Date: 03/29/04


Date: Mon, 29 Mar 2004 10:07:59 +0200

Dear all,

I try to audit a folder and its subdirectory for deletion.

The folder is located on a domain controller. I understand I have
first to enable in local security policy, audit policy, audit object
access. After that I go to Windows Explorer, select the folder, right
click it, poperties, security, advanced, auditing, add.

The result I see in the event viewer under security. Basicalyl it
works, but I see a lot of other activity for registry keys, mmc.exe as
soon as I have activate the policy. Is that normal? It quickly files
the audit log. All I want to see there is entries for auditing the
folder.

Best regards
Edy



Relevant Pages

  • RE: Auditing file deletion
    ... regarding this in the security event log. ... Default Domain Controllers Policy. ... Click Computer Configuration, double-click Windows Settings, ... double-click Audit Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Auditing file deletion
    ... You won't have to wade through the tonnes of audit logs, but have to set filters to watch the activity you care about. ... The problem is that hundreds of other Object Access events get logged, not just the file and directory deletions. ... regarding this in the security event log. ... Default Domain Controllers Policy. ...
    (microsoft.public.windows.server.sbs)
  • RE: Auditing Workstation logons from DC
    ... You have already configured Domain Security Settings for Audit account ... the both Default Domain Controllers Policy and Default Domain Security ... GPO may be overriding the audit policy setting that you configured. ...
    (microsoft.public.windows.server.sbs)
  • Re: Autoexec.nt file missing?
    ... you can't enable Auditing on a computer running Home Edition. ... You must specify what to audit. ... >> example, a file, folder, registry key, printer, and so forth-that has its ...
    (microsoft.public.windowsxp.newusers)
  • Re: audit folder/file delet
    ... >size of the security log and only audit the bare number of permissions for the bare ... >> I try to audit a folder and its subdirectory for deletion. ... >> first to enable in local security policy, audit policy, audit object ...
    (microsoft.public.win2000.security)