Re: Auditing.. We all love it...



There are a lot of 3rd party products out there that do a better job of
collating security event logs, sounds like one might be useful for you.
These typically allow you to filter out the garbage you don't want to see
and lets you check logs from several servers from the one console. e.g.
http://www.gfi.com/lanselm/

"Drumgod" <Drumgod@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DF18B7ED-1663-4A30-A312-818EFB6F55E3@xxxxxxxxxxxxxxxx
> All,
>
> I am working at a government site. The security here is really high. I
> have
> to enable auditing for the entire %SystemDrive% on each workstation.
> That's
> the easy part.
>
> I have the auditing configured using a GPO Computer Configurations |
> Windows
> Settings | Security Settings | File System. I have setup a standard set of
> NTFS permissions, and I have applied auditing to the entire drive using
> this
> GPO. Now, when I view my security log file I have WAY TOO MANY 'SYSTESM'
> audits for object access. Now, object access is what Im trying to audit
> for
> all users, but not for the system. Im mean, who really cares what the
> system
> is doing...
>
> So my question is , how to I audit object access for all users and omit
> the
> system activites from being audited. ???
>
> I have auditing setup to audit anyone in the authenticated users group. If
> I
> change this to say, domain users, will the system object access events
> leave
> my secuirty log?????
>
> Any ideas??? (BTW, Auditing SUCKS!)
>
> Drum on .. .. . . .


.



Relevant Pages

  • Re: Cannot see audit events in security log
    ... If auditing of object access for success and failure has been enabled in the ... Local Security Policy on that computer and auditing has been ... should be recorded in the security log after trying to access the folder as ...
    (microsoft.public.win2000.security)
  • Re: File Access Auditing on Exchange 2003 Server
    ... Auditing of object access can make a huge amount of entries in the security ... log even when you have not enabled auditing on any folders yet. ...
    (microsoft.public.windows.server.security)
  • Re: Folder reappeares on desktop
    ... Enabling auditing of object access generates a lot of system events such as those ... I would be looking for an Event ID 560 for the parent folder where the ... security log when that happens but it is worth a try. ...
    (microsoft.public.win2000.security)
  • Re: Auditing.. We all love it...
    ... The security here is really high. ... > to enable auditing for the entire %SystemDrive% on each workstation. ... object access is what Im trying to audit ...
    (microsoft.public.win2000.group_policy)
  • RE: Audting object access on a DC
    ... Auditing "Object Access" in AD will log any and all object access throughout ... the folders you want audited and your logs will reflect that. ... I need to audit a directory on ...
    (microsoft.public.windows.server.active_directory)