File auditing not working, need help



We're having a problem with files "disappearing" from an SBS 2003-based
network share and I'm trying to set up an audit so we can find out
what's happening to them.

I've tried the following but I'm getting no audit entries in the
security log.

Setup Steps
-----------

Steps performed on the domain controller where the share is located,
unless otherwise noted:

1. Setup Auditing at file system folder:
- Added an entry for the "Everyone" group to monitor folder and file
successful/failed deletes.
- Propogated the audit entry to all children.
- Tested: Created and deleted a file (on the server, logged in as
admin).

2. Setup an audit GPO:
- Created new GPO called "Audit Policy"
- Edited and set Windows Settings > Security Set > Local Pol > Audit
Pol > Audit Object Access to Enabled (both success and fail)
- Linked GPO to domain
- Ran gpupdate on server

3. Tested:
- Ran GP model, verified "Audit Policy" is being applied.
- Test 1: Created and deleted a file (on the server, logged in as
admin), no entries were added in the DCs security log (the server where
the files are physically stored).
- Test 2: Created and deleted a file (on the suspects NT4
workstation, logged in as the suspect), no entries were added in the
DCs security log (the server where the files are physically stored).

In every test, there were no related entries added to the security log
on the DC where the files are stored/shared. There are the usual
numerous logon/logoff entries, but that's it.

Am I missing some steps?

Thanks in advance,

James

.



Relevant Pages

  • RE: database server audit tools
    ... For ongoing audit accountability and regulatory compliance via log ... Subject: database server audit tools ... please send me also some links to harden my database server from attacks.. ... Audit your website security with Acunetix Web Vulnerability Scanner: ...
    (Pen-Test)
  • RE: audit a terminal services session on W2K Advanced Server
    ... I understand that you want to enable the auditing for terminal server. ... Enable audit for rdp-tcp connection in Terminal Services Configuration. ... Event 683 for session disconnection ...
    (microsoft.public.win2000.security)
  • Re: Hacked
    ... *audit every account and group membership. ... and old or temp accounts reset or disable ... "Newell White" wrote in message ... I've done a full scan and the server is clean. ...
    (microsoft.public.security)
  • Re: Hacked
    ... *audit every account and group membership. ... and old or temp accounts reset or disable ... "Newell White" wrote in message ... I've done a full scan and the server is clean. ...
    (microsoft.public.security)
  • RE: Audit to track moving of folders
    ... SBS server. ... "Success" Audit object access, and only monitor the following activities on ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)