Auditing deleted files / folders on a windows 2008 fileserver

I have a windows 2008 fileServer that I cannot seem to audit the deleted files and or folders;
I go to the drive then go to the folder containing the shares that I want to audit, then right click and go to properties, then select the security tab, then select advanced down at the lower right, then select the auditing tab, hit edit and then click add, add domain users, I check the boxes delete suubfolders and files, and delete, then click okay. I've tried creating and deleting file and folders from the audited folders with no entries in the security log.
This is a domain environment
LVL 1
jmpattersonAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
Did you turn on auditing on the file server itself

Computer Configuration | Windows Settings | Security Settings | Local Policies | Audit Policy

Audit Object Access

Once you enable that then you do what you did on the folders.

You can set the policy locally or via a group policy linked at a higher level that applies to the file server

Thanks

Mike
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jmpattersonAuthor Commented:
I Should have remembered that! THANK YOU!!!
0
Mike KlineCommented:
no problem, glad to help out.  Have a great weekend.

Thanks

Mike
0
arnoldCommented:
your local policy might be overwritten by a domain GPO.
with DFS you have to make sure the same security permissions exist on all targets or you will run into a huge issue where one allows the move while the other does not and you will have data all over the place.

Are there common users to the folders that "move" sticky mouse issue.

run icacls


Using security and applying the deny delete to the specific folder only for all domain users, should prevent it from being moved.
test first. create a test folder, add the rule, and using a standard account, try to move it.

potentially the sticky mouse deals with users who view folder content in explorer view.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.