logging on domain

Hi,

We are currently being audited, and one thing that has come up is that we do not keep logs of changes to active directory, folder share access basically anything to do with the network.

Can you please tell me the best way to log all of this, and hold onto the data for at least a year.  Ideally i would like it in one central database that i can look at.

thanks

phil
philipfarnesAsked:
Who is Participating?
 
AwinishConnect With a Mentor Commented:
You can have centralize storage or disc to store the logs into it.

http://technet.microsoft.com/en-us/library/cc731607%28WS.10%29.aspx

You can also consider manageenginer tool, its really good.
http://www.manageengine.com/products/active-directory-audit/

0
 
Brian PiercePhotographerCommented:
You can enable auditing - to keep the records for more than a few weeks you will need to set up a process to archive the event logs on a regular basis - there is a nice intro at http://www.techrepublic.com/article/solutionbase-creating-a-windows-server-2003-audit-policy/6028421
0
 
Muzafar MominCommented:
user netwrix change auditor
0
 
Premkumar YogeswaranAnalyst II - System AdministratorCommented:
Hi,

The best way we use..!

enable the Active directory audit logs in AD
http://technet.microsoft.com/en-us/library/cc731607(WS.10).aspx

And also use a 3rd party software fro quest change auditor
http://www.quest.com/changeauditor-for-active-directory/

Regards,
Prem
0
 
ActiveDirectorymanCommented:

You can also use SPLUNK for auditing your Active Directory Environment.  i would also setup event forwarding depending on the size of your environment in windows.  If you have less than 10 servers it would be a good idea.  

With event forwarding  you can forward your event log data to one box and have a centralized location for yout logging.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.