A
A
Andrey Tatarnikov2015-11-03 12:17:12
Windows Server
Andrey Tatarnikov, 2015-11-03 12:17:12

How to properly configure Windows Server 2012 file server access auditing?

Tell me how to properly configure the file share audit so that:
1. The creation of the file can be seen
2. The change in the file name (the old name and the new name)
can be seen 3. The change in the file can be seen
4. The deletion of the file can be seen
I made such an audit setting for the share folder :
4b3fab666ba04b05a64cd151016eade3.png
Enabled the policy.
At the same time, ReadData events are poured into the logs, which are many and which are not needed.
But there are no normal file rename events: when renaming, a DELETE event occurs for the old name, the new name is not visible at all.
How do people live with it? Or is there some third-party software that can competently subscribe to file system events and write a log?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
S
Sergey Kovalev, 2015-11-03
@Sergey-S-Kovalev

Auditing changes on file servers with standard tools is a pain. Incessant.
At one time they praised Netwrix Auditor for File Servers , I don’t know how it is with it now.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question