Solved

Auditing %SystemRoot%\system32 or c:\windows\system32 Files

Posted on 2009-07-06
3
725 Views
Last Modified: 2012-05-07
I have two questions for this subject:

1.  What is the difference between the SystemRoot location and the "windows" location?

2.  If I need to set auditing for specific files within the \system32 directory, does it matter if I set it through SystemRoot or in the \system32 directory?
0
Comment
Question by:myoutback
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 10

Accepted Solution

by:
PlusIT earned 125 total points
ID: 24784982
1.  the difference is that the SystemRoot is a variable poointing to your windows installation.  Not everyone installs c:\windows by using for example %systemroot%\system32 you are sure you can browse to the system32 folder even if your windows is not installed in C.
Try this by opening a cmd shell and echo the variable with the command: echo %SYSTEMROOT%

2.  try to use variables as much as you can.
0
 

Author Comment

by:myoutback
ID: 24793821
Thanks for the explanation.

If I wanted to set auditing to %SystemRoot%\system32\activeds.dll from the cmd shell, what would it look like?
0
 
LVL 10

Assisted Solution

by:PlusIT
PlusIT earned 125 total points
ID: 24801766
i'm not sure tbh never done it myself this maybe can help you:
http://technet.microsoft.com/en-ca/magazine/2008.08.scom.aspx
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
OLD TECH - PKZIP Only Zips 7 Files 17 112
UAC Controls - confused 9 94
SHA2 certs for IIS AND Java? 2 122
system default settings 4 21
Sometimes people don't understand why download speed shows differently for Windows than Linux.Specially, this article covers and shows the solution for throughput difference for Windows than a Linux machine. For this, I arranged a test scenario.I…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question