Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Auditing file access

Status
Not open for further replies.

alex0628

MIS
Sep 29, 2004
64
I using a Windows 2000 server with AD. I set up auditing under group policies. I used the DomainUser group since everyone belongs to that group. I also set up auditing on specific folders, again using DomainUsers group. But, under the Security log, the only events I see are login/logout. I had someone delete a file from one of the folders and nothing logs. What am I missing?
 
Make sure of the following;

1. Have you enabled auditing of object access in your security policy and have set it to Success/Failure
2. When enabling auditing on a folder I is usually use the Everyone group (although Domain users should suffice this doesn't stop the local administrator from logging on and deleting files)
3. What permissions are you audting. Check off everything but full control for the group. and ensure you have set it for the folders and subfolders of the folder you are auditing.

Hope this helps
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top