it_gsr
asked on
auditing file access on a server
First, i "turn on" auditing in general on my file server, using either the local security policy and on the domain policy for the servers in question.
Then i enabled auditing for the users or groups in question on the folders that are of interest. After logging on and deleting a folder which i have access to, i cann't see anything in the security event logs. need help
Then i enabled auditing for the users or groups in question on the folders that are of interest. After logging on and deleting a folder which i have access to, i cann't see anything in the security event logs. need help
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks guys. But what will be the event id for delete and what are the other event id's in auditing?
Cheers
Cheers
How long did you wait with deleting the folder after you set up the policy?? It can take up to 90 minutes before policies are refreshed. You can force it using these commands..
secedit /refreshpolicy on Windows 2000
gpupdate /force on XP and Server 2003