audit success access


C

CEDRIC

Thanks for your answer... I have 150 users's directory and
i want to audit failed access on these directory and
succesful permission change.
When i enable auditing of object access on Local security
Policies for FAILED and on object enbale FAILED for read
write > No problem only failed access of users appear

When i enable auditing of object access on Local security
Policies for SUCCESS and on object enbale SUCCESS for
permission change > Lot off event of the user "NT
AUTHORITY\SYSTEM" with ID 560 and 562.

My problem is that i have write a script and put this
script in service to look permanently eventlog to send a
mail alert if event id 560 and 612 appear. I doesn't want
to disable on object audit everybody for the security i
want to now if anyone try to access on these directory.
After one week of research i begin to now what it's a bug
or a forget on W2K because i have try to XP and no problem.

Thanks for your help,
Cedric
 
Ad

Advertisements


Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top