Click here to get back home

Monitoring to see if a file is copied

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Monitoring to see if a file is copied Jason Ede 09-20-2006
Posted by Jason Ede on September 20, 2006, 10:29 am
Please log in for more thread options
Hi,

I've been trying to work out an easy method of detecting if a file is
copied off the server by a remote computer/user. By enabling object
access in the audit logs for the domain controller it shows this in the
event logs, but the log very quickly fills up with normal usage. Is it
possible to only enable object access logging for 1 area or is there
another way to determine if a file is copied and who by?

Jason

Posted by Roger Abell [MVP] on September 21, 2006, 12:30 am
Please log in for more thread options
You ask if one may enable such auditing for only one area.
Yes, certainly, even just for one file. Recall that one does
not need to only enable audit of object access, but also to
go into the NTFS security dialog's Advanced view and set
audit specifications in the Audit tab. If you did not need to
do this last step, then someone had done so earlier. Audit
records will only be written for access in areas where this
has been done and only for the accesses that were specified.

Note however, you cannot audit "copies" but you can audit
reads. The other part of a copy is a write somewhere else,
which cannot be audited on the read-from area.
> Hi,
>
> I've been trying to work out an easy method of detecting if a file is
> copied off the server by a remote computer/user. By enabling object access
> in the audit logs for the domain controller it shows this in the event
> logs, but the log very quickly fills up with normal usage. Is it possible
> to only enable object access logging for 1 area or is there another way to
> determine if a file is copied and who by?
>
> Jason



Similar ThreadsPosted
Monitoring users April 18, 2006, 12:55 pm
application monitoring May 6, 2007, 5:11 pm
User web activity monitoring October 29, 2007, 10:16 am
Spam monitoring yahoo details June 24, 2005, 12:27 pm
Monitoring of Internet Usage by Staff March 2, 2006, 6:17 am
Remote monitoring of NT services in Windows Servers. April 20, 2006, 7:08 am
Read-only access to AD, 2000, and 2003 server for monitoring? September 7, 2007, 3:20 pm
ASP.NET Performance Counters don't work monitoring several remote 2003 servers. February 1, 2007, 12:46 pm
Able to Mount File Share With File Print Sharing Off October 28, 2006, 10:14 pm
File Access Audit on File Server June 20, 2007, 4:59 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap