Solved

Query Windows audit settings using WMI

Posted on 2013-05-24
4
1,105 Views
Last Modified: 2013-05-25
Using REALbasic with the Monkeybread WMI plugin, I can query 57 of the 59 RSOP_xxx classes without error, but I only get data returned for these eight:
    RSOP_ExtensionEventSource
    RSOP_ExtensionEventSourceLink
    RSOP_ExtensionStatus
    RSOP_GPLink
    RSOP_GPO
    RSOP_PolicySetting
    RSOP_Session
    RSOP_SOM

I'm guessing that there is some security setting that keeps WMI from returning data for the other ones for which I know data exists -- specifically
    RSOP_AuditPolicy
    RSOP_RegistryKey
    RSOP_RegistryPolicySetting
    RSOP_RegistryValue
and some others.

Any ideas?
0
Comment
Question by:Roland_F
  • 2
  • 2
4 Comments
 
LVL 80

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 39196764
if you use wmispy or other wmi tools i.e. powershell does it return a proper value?
0
 

Author Comment

by:Roland_F
ID: 39196839
I don't know - I've never touched WMI except with VB and this current code. I'll do a little research and try to find out.
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 39196851
0
 

Author Comment

by:Roland_F
ID: 39196897
I could not find a download for WniSpy from a source I considered reliable. i did find WMI Explorer, though, which is a very handy free tool. Using WMI Explorer I find that those classes that don't return any data don't have any instances -- which is frustrating because I have done considerable work with secpol.msc to establish security and audit policies. Anyway, I will accept this one response as the solution to this particular problem. Have to look farther to get where I need to go. Thanks.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question