auditing of object access

Discussion in 'Scripting' started by CEDRIC, Sep 30, 2003.

  1. CEDRIC

    CEDRIC Guest

    Thanks for your answer... I have 150 users's directory and i want to audit failed access on these directory and succesful permission change.
    When i enable auditing of object access on Local security Policies for FAILED and on object enbale FAILED for read write > No problem only failed access of users appear

    When i enable auditing of object access on Local security Policies for SUCCESS and on object enbale SUCCESS for permission change > Lot off event of the user "NT AUTHORITY\SYSTEM" with ID 560 and 562.

    My problem is that i have write a script and put this script in service to look permanently eventlog to send a mail alert if event id 560 and 612 appear. I doesn't want to disable on object audit everybody for the security i want to now if anyone try to access on these directory. After one week of research i begin to now what it's a bug or a forget on W2K because i have try to XP and no problem.

    Thanks for your help,
    Cedric
     
    CEDRIC, Sep 30, 2003
    #1
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.