WINSERVER2008R2 log file deletion with "Audit object"

Source: Internet
Author: User
Tags ntfs permissions

There are pros and cons, this opposite is always there, and file share access has the same problem. Although it is possible to control the permissions of the user through NTFS permissions and within the domain, it is difficult to manage the rights of each individual user, so there is always such a problem in the actual application, such as a file that has been deleted by some unknown person. In the end, everyone has to shirk responsibility, because a folder is shared with some people, so even if you know someone who deleted the file, but you do not know the specific person.

Although deleted files can be retrieved by shadow copy or other backup means, but after all the trouble, if you can let the system record this event is better, there is system record can not evade, follow the following steps to achieve the file deletion event in the shared directory record.

1. Open the Group Policy Editor, navigate to "Computer Configuration →windows settings → security settings → local policies → audit Policy", double-click "Audit object Access" on the right, tick "Define these policy settings" and "Success", "failed" entry does not need to tick.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/47/CF/wKioL1P_0_ug_VftAAOpZLvl5eI666.jpg "title=" 1.png " alt= "Wkiol1p_0_ug_vftaaopzlvl5ei666.jpg"/>

2. Add Audit users

Right-click the shared folder that needs to be audited, select Properties, switch to the Security tab, click the Advanced button, switch to the Auditing tab in the New dialog box, add users, groups to approve, and tick and delete related items in the auditing project.


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/47/CF/wKioL1P_1DfRNd7TAAOEkbunx10553.jpg "title=" 0.png " alt= "Wkiol1p_1dfrnd7taaoekbunx10553.jpg"/>


To the specified shared directory, delete a file with the user of the audited record, and event 5663 deletes the record in the system's security log.


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/47/CE/wKiom1P_04PiUX00AAWFZAY--_Y311.jpg "title=" 2.png " alt= "Wkiom1p_04piux00aawfzay--_y311.jpg"/>





This article is from the "Anthony Big Group" blog, please be sure to keep this source http://52czy.blog.51cto.com/3704825/1546362

WINSERVER2008R2 log file deletion with "Audit object"

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.