Auditing-- where?? and why ??

Auditing-- where?? and why ??

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Auditing-- where?? and why ?? Eng.Rana 07-13-2006
Posted by on July 13, 2006, 3:12 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear All,
i hope u r all fine :)

i found that for a secure system u should be auditing ur system
events??
i don c how such a thing adds a level of security??

so i decided to audit my system events and logons using the gpedit.msc,
but i was wondering where r the auditing files stored, where can i view
the events previously auditted??
and how can i benefit from it


thanx for ur gr8 help and time :)


Posted by Malke on July 13, 2006, 7:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Eng.Rana@gmail.com wrote:

> Dear All,
> i hope u r all fine :)
>
> i found that for a secure system u should be auditing ur system
> events??
> i don c how such a thing adds a level of security??
>
> so i decided to audit my system events and logons using the gpedit.msc,
> but i was wondering where r the auditing files stored, where can i view
> the events previously auditted??
> and how can i benefit from it

That's a pretty sweeping statement and one that I question. It really
depends on your situation and what you mean by auditing system events. We
don't know if you have a standalone machine (running what OS?) or a domain
server taking care of 250 clients. We don't know if this is something you
heard from "a friend's cousin who knows something about computers" or you
are actively trying to harden your server. You will get more focused
answers if you provide more information. Oh, and if you do want more help
please take the time to use conventional English instead of text messaging
abbreviations. This is not a chat room and it makes your post difficult to
read. This will limit your responses.

In the meantime:

Audit User Access of Files, Folders, and Printers in Windows XP -
http://support.microsoft.com/Default.aspx?kbid=310399

Audit Active Directory Objects in Windows Server 2003 -
http://support.microsoft.com/Default.aspx?kbid=814595

To add users or groups to the audit list - http://tinyurl.com/lozjc

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by karl levinson, mvp on July 13, 2006, 8:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> i found that for a secure system u should be auditing ur system
> events??
> i don c how such a thing adds a level of security??
>
> so i decided to audit my system events and logons using the gpedit.msc,
> but i was wondering where r the auditing files stored, where can i view
> the events previously auditted??
> and how can i benefit from it

Auditing lets you control and see what is happening on your system. One day
you will want to know what some user has been doing, or whether your system
has been hacked. Log files such as auditing logs are your friend here. If
you don't configure this before you have this question, that information is
unavailable to you. You don't have to enable auditing if you don't want,
but most people do consider auditing to be necessary on systems where
security is important.

Windows auditing is logged to the Windows Security Event Log. Be careful
not to enable too much auditing. Note that there are a variety of different
kinds of auditing, such as logon auditing and NTFS file access auditing. To
enable file access auditing is a two step process: turn on the auditing in
group policy, and then set the auditing properties on each file and folder
that you wish to audit. More info is at:

http://securityadmin.info/faq.asp?auditing

Recommendations for what levels of auditing to enable are in the Windows
Security Guide for your version of Windows, which can be found at
www.microsoft.com/technet/security

--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
--------------------------------
Microsoft Security FAQ:
http://securityadmin.info



Similar ThreadsPosted
Auditing December 20, 2006, 8:37 am
Auditing folders December 20, 2005, 8:42 am
Class on Rights and Auditing July 18, 2005, 2:41 pm
Auditing Account Management September 23, 2005, 12:06 pm
auditing for forensic purposes October 14, 2005, 6:48 am
Auditing Workstation logons from DC January 24, 2006, 1:16 pm
Auditing File deletion April 19, 2006, 3:26 am
Email Access Auditing June 11, 2007, 10:41 am
Auditing shared folder April 7, 2008, 1:02 pm
Auditing / File Security May 22, 2008, 1:02 pm

The site map in XML format XML site map

Contact Us | Privacy Policy