Re: Auditing.. We all love it...



Remember that the system is a security principal too and a consumer of
system resources, thus creating events. You can filter events so you don't
see them. This might be the best way to get what you want.

--
Ryan Hanisco
MCSE, MCDBA
FlagShip Integration Services
Chicago, IL

"Drumgod" <Drumgod@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DF18B7ED-1663-4A30-A312-818EFB6F55E3@xxxxxxxxxxxxxxxx
> All,
>
> I am working at a government site. The security here is really high. I
> have
> to enable auditing for the entire %SystemDrive% on each workstation.
> That's
> the easy part.
>
> I have the auditing configured using a GPO Computer Configurations |
> Windows
> Settings | Security Settings | File System. I have setup a standard set of
> NTFS permissions, and I have applied auditing to the entire drive using
> this
> GPO. Now, when I view my security log file I have WAY TOO MANY 'SYSTESM'
> audits for object access. Now, object access is what Im trying to audit
> for
> all users, but not for the system. Im mean, who really cares what the
> system
> is doing...
>
> So my question is , how to I audit object access for all users and omit
> the
> system activites from being audited. ???
>
> I have auditing setup to audit anyone in the authenticated users group. If
> I
> change this to say, domain users, will the system object access events
> leave
> my secuirty log?????
>
> Any ideas??? (BTW, Auditing SUCKS!)
>
> Drum on .. .. . . .


.



Relevant Pages

  • Re: auditing
    ... Enable auditing of account management will log the creation and changes to ... You can audit Directory Service access to audit OU's. ... This security setting determines whether to audit each event of account ... For specific instructions about how to configure auditing policy settings, ...
    (microsoft.public.win2000.active_directory)
  • Re: How to determine who changed permissions on a directory?
    ... I used the "Security Monitoring and Attack Detection Planning Guide" from ... Audit Account Logon events - Success, Failure ... Audit Object Access - Success, ...
    (microsoft.public.security)
  • Re: How to determine who changed permissions on a directory?
    ... I used the "Security Monitoring and Attack Detection Planning Guide" from ... Audit Account Logon events - Success, Failure ... Audit Object Access - Success, ...
    (microsoft.public.security)
  • HELP - File Auditing
    ... not automatically trigger any new "object access" audit ... individual objects for audit events to be logged. ... To enable auditing on a file/directory do the following: ... GPEDIT.msc in that server, ...
    (microsoft.public.win2000.security)
  • Re: User activity log
    ... You can enable auditing of object access in Local Security Policy or the ... folders/files you want to track. ... For instance you can audit an executable ...
    (microsoft.public.windows.server.security)