Enabling Object Access Auditing Shows no Events in the Security Log


so i've followed steps enable object access auditing.  on new windows server 2008 standard machine acting ad / dns / file server / dhcp.  went default domain policy , enabled success , failures object access auditing.  went main share file server , selected directory contains autocad projects i'd monitor.  went in auditing tab , added user group parameters checked except 'full control'.  i've waited standard gp refresh interval of 90 minutes.  nothing appears in event logs though can plainly see there many open files share , storage management snap-in.  before this, tried auditing user group 'engineers' , nothing appeared in logs.  think security log flooded events no auditing seems happening.  note, i'm still able see things logon successes , active directory audits in security log.  maybe point out of workstations accessing server still running xp pro sp3.  ideas why happening , how can fix great.

best,
scott daniel

ok, figured out.

forgot file server domain controller 'default domain controller policy' being applied , overriding 'default domain policy'.  in default domain controller policy, object access marked "no auditing".  changed success, failure , worked!


Windows Server  >  File Services and Storage



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group