Solved

Query Windows audit settings using WMI

Posted on 2013-05-24
4
1,122 Views
Last Modified: 2013-05-25
Using REALbasic with the Monkeybread WMI plugin, I can query 57 of the 59 RSOP_xxx classes without error, but I only get data returned for these eight:
    RSOP_ExtensionEventSource
    RSOP_ExtensionEventSourceLink
    RSOP_ExtensionStatus
    RSOP_GPLink
    RSOP_GPO
    RSOP_PolicySetting
    RSOP_Session
    RSOP_SOM

I'm guessing that there is some security setting that keeps WMI from returning data for the other ones for which I know data exists -- specifically
    RSOP_AuditPolicy
    RSOP_RegistryKey
    RSOP_RegistryPolicySetting
    RSOP_RegistryValue
and some others.

Any ideas?
0
Comment
Question by:Roland_F
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 82

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 39196764
if you use wmispy or other wmi tools i.e. powershell does it return a proper value?
0
 

Author Comment

by:Roland_F
ID: 39196839
I don't know - I've never touched WMI except with VB and this current code. I'll do a little research and try to find out.
0
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 39196851
0
 

Author Comment

by:Roland_F
ID: 39196897
I could not find a download for WniSpy from a source I considered reliable. i did find WMI Explorer, though, which is a very handy free tool. Using WMI Explorer I find that those classes that don't return any data don't have any instances -- which is frustrating because I have done considerable work with secpol.msc to establish security and audit policies. Anyway, I will accept this one response as the solution to this particular problem. Have to look farther to get where I need to go. Thanks.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

631 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question