Re: Audit file/folder access



You choose what file or folder you wish to audit and using NTFS security
tab, auditing tab and choose for Everyone what to audit. Unfortunately
Systemaccount is also included in Everyone so you won´t get rid of those
entries.

--
----------------------------------------------------------------------------------------------------------------------------
Johan Engdahl
CCSA, CCSE, CCA, MCP | johan AT firewall1 DOT nu | http://www.firewall1.nu

"Hugo" <hugorobichrg@xxxxxxxxxxxxxx> wrote in message
news:uKaUI3rTHHA.3980@xxxxxxxxxxxxxxxxxxxxxxx
Hi Everyone !

I activated "Audit Object Access" with "Success and Failure" in a GPO for
one of my server. Without configuring any File/Folder for Audit (or any
other objects), my Security Event Log is filling up with files access
(normal user and System) for file access on C: and D: drives and registry
access for System user !!!

What can I do to not have those events in my event log ?

I want to monitor only one directory on D: drive...

Any idea ?

Thank you !

Hugo

PS: Sorry for my bad english, I'm french speaking !



.



Relevant Pages

  • Re: How to monitoring who has deleted a NTFS folder
    ... If when adding the auditing ACE in the Auditing tab within the Security ... I know you said audit policies don't solve the problem. ... Now when a user deletes any subfolders you will get an entry in your ...
    (microsoft.public.windows.server.security)
  • Re: File share audit
    ... On the folder properties go to security tab, advanced, auditing tab and add the user or group you like to audit and set the options for auditing. ...
    (microsoft.public.windows.server.general)
  • Re: Audit
    ... First question to ask is "Audit what?". ... Files access can be audited based on any ... group, including Admins. ...
    (microsoft.public.win2000.active_directory)
  • Re: Audit file/folder access
    ... For the folder I want to audit, I use a more restrictive group than ... My problem is that before adding any audit using NTFS security, ... my Security Event Log is filling up with files access ... What can I do to not have those events in my event log? ...
    (microsoft.public.windows.server.security)
  • Re: Script to enable auditing on all client PCs in a Domai
    ... This posting is provided "AS IS" with no warranties, ... Can Any one help me to write a script to audit C: ... But to add a new entry in auditing tab of any folder can any one help ...
    (microsoft.public.windows.server.general)