Re: Utility to monitor who accesses a particular directory?



I think you want to look at event log management type tools then that can give you more of a spoon fed view. It would be silly to add another device driver to do something that is already available.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


MS wrote:
Hi, We have a directory with sensitive information that we would like to monitor to see who accesses it and attempts to access it. I have auditing enabled, but the logs are difficult to read and understand.

Ideally, I would like a program that monitors a directory, and writes to a log file each time someone accesses it, or attempts to (we're in an AD environment). It would be nice to be able to exclude the system and backup accounts from being logged.

Does anyone know of a utility that can do this? Thanks,


.



Relevant Pages

  • Re: logging data accessed by user
    ... > and set a SACL to trigger event messages on all accesses. ... I question whether even if you did monitor ... > the event log and detect such accesses within an actionable time ...
    (microsoft.public.win2000.security)
  • Re: Utility to monitor who accesses a particular directory?
    ... driver to do something that is already available. ... monitor to see who accesses it and attempts to access it. ... a log file each time someone accesses it, or attempts to (we're in an AD ...
    (microsoft.public.windows.server.security)
  • Utility to monitor who accesses a particular directory?
    ... monitor to see who accesses it and attempts to access it. ... I have auditing ... log file each time someone accesses it, or attempts to (we're in an AD ...
    (microsoft.public.windows.server.security)
  • Utility to monitor who accesses a particular directory?
    ... monitor to see who accesses it and attempts to access it. ... I have auditing ... log file each time someone accesses it, or attempts to (we're in an AD ...
    (microsoft.public.windows.file_system)