Guest Kelly Armitage Posted May 30, 2008 Posted May 30, 2008 We have a Windows 2003 domain controller and have enabled auditing on our public shares to track when (and who) has deleted any files. It works great and logs it accordingly on the DC security events. The problem is that if someone were to just MOVE the files (because they have the applicable persmissions) it does not log anything. This seems like a giant loophole to me and I am assuming I am missing something. Is there any way I can use security/file auditing to track when someone has moved a file? I do not see that as one of the listed options from the security/advanced/auditing tab. Any help or suggestions welcome... thank you in advance. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.