Link to home
Start Free TrialLog in
Avatar of it_gsr
it_gsr

asked on

auditing file access on a server

First, i "turn on" auditing in general on my file server, using either the local security policy and on the  domain policy for the servers in question.
Then i enabled auditing for the users or groups in question on the folders that are of interest. After logging on and deleting a folder which i have access to, i cann't see anything in the security event logs. need help
Avatar of rhandels
rhandels
Flag of Netherlands image

Hi,

How long did you wait with deleting the folder after you set up the policy?? It can take up to 90 minutes before policies are refreshed. You can force it using these commands..

secedit /refreshpolicy on Windows 2000
gpupdate /force on XP and Server 2003
ASKER CERTIFIED SOLUTION
Avatar of mcp_jon
mcp_jon
Flag of Portugal image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of it_gsr
it_gsr

ASKER

Thanks guys. But what will be the event id for delete and what are the other event id's in auditing?

Cheers