Can native OS tools enable file-access auditing?

Can native OS tools enable file-access auditing?

I've read somewhere that file-access auditing can be enabled and subsequently reported using native OS tools, rather than third-party tools. Is this correct? Or is a third-party solution required to determine who accesses what and when on a Windows server?

    Requires Free Membership to View

    By submitting your registration information to SearchWindowsServer.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchWindowsServer.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

The native OS has the ability to audit file objects and can report successful and failed attempts to access an object. It then places those reports into the system security event log.

This article explains how to use Group Policy to apply or modify auditing policy settings for an object.

Once you've set this up, locate a utility that can send you the specific security events that appear in the server you're auditing (or do some scripting if you know how). I suggest the EventSentry Light utility from Event Sentry. This freeware program runs without time limitations and allows you to specify the events to send your way.

This was first published in September 2007

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.