File auditing for MOVED files.


Kelly Armitage

We have a Windows 2003 domain controller and have enabled auditing on our

public shares to track when (and who) has deleted any files. It works great

and logs it accordingly on the DC security events. The problem is that if

someone were to just MOVE the files (because they have the applicable

persmissions) it does not log anything. This seems like a giant loophole to

me and I am assuming I am missing something. Is there any way I can use

security/file auditing to track when someone has moved a file? I do not see

that as one of the listed options from the security/advanced/auditing tab.

Any help or suggestions welcome... thank you in advance.

Top Bottom