Click here to get back home

Audit Policy (security logs)

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Audit Policy (security logs) SBN via WinServerKB.com 08-20-2007
Posted by SBN via WinServerKB.com on August 20, 2007, 10:18 pm
Please log in for more thread options
Hey guys im trying to implement audit policy in our network and im trying to
test it. i setup a certain folder to be audited and i tried to create a file,
delete a file, move a files and check the security log events. and theres a
lot of security logs about the activity that i did but on the logs there are
so many. my problem now is that how can i differentiate and determined the
log saying that this file has been move to here, this file has been deleted,
or this file has been created.

hope you can help guys:)

--
Message posted via http://www.winserverkb.com


Posted by S. Pidgorny on August 21, 2007, 7:03 am
Please log in for more thread options
By analysing the event information?
There is no tool (that I'm aware of) that will reconstruct the events logged
into a simple sequence of user activities that led to the events.

The best approach to minimise the log noise is to monitor for exceptions
i.e. somebody reads a file that no one is supposed to read (a honeytoken),
or somebody is changing permission on the bosses' file share.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hey guys im trying to implement audit policy in our network and im trying
> to
> test it. i setup a certain folder to be audited and i tried to create a
> file,
> delete a file, move a files and check the security log events. and theres
> a
> lot of security logs about the activity that i did but on the logs there
> are
> so many. my problem now is that how can i differentiate and determined
> the
> log saying that this file has been move to here, this file has been
> deleted,
> or this file has been created.
>
> hope you can help guys:)
>
> --
> Message posted via http://www.winserverkb.com
>



Similar ThreadsPosted
Help Needed in interpreting Security Audit Logs December 27, 2006, 10:36 am
Audit Policy Settings February 8, 2006, 3:46 pm
Detail display for audit policy December 19, 2006, 9:06 pm
How to use registry to lock the Audit Policy October 5, 2008, 8:07 am
Windows 2003 audit Policy amended October 29, 2006, 7:32 pm
Audit policy problem (deleted file name) May 28, 2007, 7:21 am
Security Logs May 30, 2007, 7:29 pm
Security Event Logs June 10, 2005, 8:36 am
security event logs in DC as well ? SOS May 3, 2006, 6:06 pm
Event ID 577 Filing Security Logs July 19, 2006, 10:45 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap