Windows File server access auditong ?

Hi People,

How can I view or generate the log of who has accessed the sensitive files in certain folders in my file server ?

The File server is Windows Server 2012 R2 and I have just enabled the FSRM features after I have done the final file copy of user Home drives last month.

Is it possible to know the access last week or do I have to enable certain feature to get the point forward logging ?
LVL 9
Senior IT System EngineerIT ProfessionalAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Lee W, MVPTechnology and Business Process AdvisorCommented:
You need to enable auditing and then you move forward from there, it's not something you can see the past for when you weren't tracking it.

This Technet article contains many details on enabling

Auditing File Access on File Servers
http://blogs.technet.com/b/mspfe/archive/2013/08/27/auditing-file-access-on-file-servers.aspx
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Senior IT System EngineerIT ProfessionalAuthor Commented:
ok, so once enabled, where can I view the access log ?
0
Lee W, MVPTechnology and Business Process AdvisorCommented:
In the Security Event Logs.  Applying a filter for your desired information is going to make it easiest to view.
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
Cool, so in this case, when someone copied a directory to another shared drive, is that going to be logged ?
0
Lee W, MVPTechnology and Business Process AdvisorCommented:
It depends on the criteria for auditing that you selected.  (DO MAKE SURE you have sufficiently large log settings - overwrite after x size or days and you could lose the information.  I also once had a client with this enabled and a setting to keep an archive of the logs - they filled his C: drive in weeks because he wasn't taking steps to offload the archived logs!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2012

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.