Click here to get back home

File Access Auditing on Exchange 2003 Server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
File Access Auditing on Exchange 2003 Server Jimmy 06-28-2005
Posted by Jimmy on June 28, 2005, 4:01 am
Please log in for more thread options
Our company has an Exchange 2003 SP1 server runs on Windows 2003 Std. It will
update to SP1 in a few weeks. The server also does file sharing for all our
40+ users.

We want to enable auditing to keep track of read/write activities on the
file shares. I did attempt turn on Success/Failure of Object Access in Local
Security Policy. I didn't turn on auditing on any File System yet. Then I
discovered a lot of Exchange object access (ID 562) were tracked in security
log. Size increase is more than 6MB for merely an hour. That makes auditing
impractical to implement.

Did I do anything wrong on the setup or this is a necessary evil of auditing
on E2K3?

Jimmy



Posted by Steven L Umbach on June 28, 2005, 9:26 am
Please log in for more thread options
Auditing of object access can make a huge amount of entries in the security
log even when you have not enabled auditing on any folders yet. One thing to
check is that in Local Security Policy [secpol.msc], or whatever appropriate
security policy, that the security option for audit:audit the access of
global system objects is disabled. I can tell you right now that keeping
track of read activities will generate a huge amount of events. When you do
audit a folder it is best to audit absolute minimum number of permissions
for absolute minimum number of users/groups and avoid auditing for everyone,
users, authenticated user groups but instead use a global/local group of
just the users you want to track. The free MS too Event Comb can help in
tracking object access events and it can search by text string such as for
filename or user name. The link below may help. --- Steve

http://www.microsoft.com/technet/security/topics/auditingandmonitoring/securitymonitoring/default.mspx

> Our company has an Exchange 2003 SP1 server runs on Windows 2003 Std. It
> will
> update to SP1 in a few weeks. The server also does file sharing for all
> our
> 40+ users.
>
> We want to enable auditing to keep track of read/write activities on the
> file shares. I did attempt turn on Success/Failure of Object Access in
> Local
> Security Policy. I didn't turn on auditing on any File System yet. Then I
> discovered a lot of Exchange object access (ID 562) were tracked in
> security
> log. Size increase is more than 6MB for merely an hour. That makes
> auditing
> impractical to implement.
>
> Did I do anything wrong on the setup or this is a necessary evil of
> auditing
> on E2K3?
>
> Jimmy
>




Posted by Jimmy on June 29, 2005, 4:05 am
Please log in for more thread options
Checked that "audit the access of global system objects" is disabled.

Jimmy

"Steven L Umbach" wrote:

> Auditing of object access can make a huge amount of entries in the security
> log even when you have not enabled auditing on any folders yet. One thing to
> check is that in Local Security Policy [secpol.msc], or whatever appropriate
> security policy, that the security option for audit:audit the access of
> global system objects is disabled. I can tell you right now that keeping
> track of read activities will generate a huge amount of events. When you do
> audit a folder it is best to audit absolute minimum number of permissions
> for absolute minimum number of users/groups and avoid auditing for everyone,
> users, authenticated user groups but instead use a global/local group of
> just the users you want to track. The free MS too Event Comb can help in
> tracking object access events and it can search by text string such as for
> filename or user name. The link below may help. --- Steve
>
>
http://www.microsoft.com/technet/security/topics/auditingandmonitoring/securitymonitoring/default.mspx
>
> > Our company has an Exchange 2003 SP1 server runs on Windows 2003 Std. It
> > will
> > update to SP1 in a few weeks. The server also does file sharing for all
> > our
> > 40+ users.
> >
> > We want to enable auditing to keep track of read/write activities on the
> > file shares. I did attempt turn on Success/Failure of Object Access in
> > Local
> > Security Policy. I didn't turn on auditing on any File System yet. Then I
> > discovered a lot of Exchange object access (ID 562) were tracked in
> > security
> > log. Size increase is more than 6MB for merely an hour. That makes
> > auditing
> > impractical to implement.
> >
> > Did I do anything wrong on the setup or this is a necessary evil of
> > auditing
> > on E2K3?
> >
> > Jimmy
> >
>
>
>


Similar ThreadsPosted
Auditing File Access January 15, 2008, 11:18 am
How Do We Avoid Auditing Failed SYNCHRONIZE File Access? July 4, 2006, 1:36 am
Cannot install DPM agent on Windows server 2003 (Exchange and IIS) June 26, 2007, 12:23 pm
File Access Audit on File Server June 20, 2007, 4:59 pm
win 2003 AD + exchange problem November 25, 2005, 11:52 am
Enterprise file auditing May 17, 2007, 8:08 pm
Access to NT4 File Ressources denied from Windows 2003 System April 7, 2006, 2:49 am
Auditing File Share Security February 5, 2007, 3:44 pm
Permissions on root c of AD & exchange server August 18, 2005, 1:45 am
Moving server 2003 CA database file location November 6, 2006, 3:35 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap