Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 285
  • Last Modified:

logging on domain

Hi,

We are currently being audited, and one thing that has come up is that we do not keep logs of changes to active directory, folder share access basically anything to do with the network.

Can you please tell me the best way to log all of this, and hold onto the data for at least a year.  Ideally i would like it in one central database that i can look at.

thanks

phil
0
philipfarnes
Asked:
philipfarnes
1 Solution
 
KCTSCommented:
You can enable auditing - to keep the records for more than a few weeks you will need to set up a process to archive the event logs on a regular basis - there is a nice intro at http://www.techrepublic.com/article/solutionbase-creating-a-windows-server-2003-audit-policy/6028421
0
 
Muzafar MominCommented:
user netwrix change auditor
0
 
AwinishCommented:
You can have centralize storage or disc to store the logs into it.

http://technet.microsoft.com/en-us/library/cc731607%28WS.10%29.aspx

You can also consider manageenginer tool, its really good.
http://www.manageengine.com/products/active-directory-audit/

0
 
Premkumar YogeswaranAnalyst II - System AdministratorCommented:
Hi,

The best way we use..!

enable the Active directory audit logs in AD
http://technet.microsoft.com/en-us/library/cc731607(WS.10).aspx

And also use a 3rd party software fro quest change auditor
http://www.quest.com/changeauditor-for-active-directory/

Regards,
Prem
0
 
ActiveDirectorymanCommented:

You can also use SPLUNK for auditing your Active Directory Environment.  i would also setup event forwarding depending on the size of your environment in windows.  If you have less than 10 servers it would be a good idea.  

With event forwarding  you can forward your event log data to one box and have a centralized location for yout logging.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now