|
|
The Auditing system is an important troubleshooting tool. If you have a problem where files are being changed or deleted unexpectedly, you can use the audit system to determine who is accessing the files and when the access occurs. Activating and viewing the audit trail for file access is done with 3 different programs.
An example troubleshooting scenario is a case where a program fails because of a file security problem. If the file with the security problem is not identified, how do you determine which security permission to change? Use auditing to determine the problem file and then change the security permissions so that you resolve the problem. The following dialog shows how Audit Policy settings are enabled. Notice how both failures and successful transactions can be audited.
The following dialog shows a SACL System Access Control List which defines a security principal and which of the security permissions will be audited. The following dialog shows the permissions of the file system. Other objects such as printers, registry keys, and AD objects, have different permissions.
The Computer Management console Event Viewer Security log shows the audit trail of audited transactions. Notice that both failures and successful transactions are shown.
|
|
|