Hey guys, I haven't seen much on here about File Auditing...I saw a few about people snooping around ETC.
I am not familiar with 2k3 as much as I'd like to be, but here is my current predicament.
We run a file-share server on Server 2k3.
We are a domain network. We login at our PCs, and depending on the user and what group they're assigned to, have access to different parts of the file share server.
Recently, in an attempt to reduce the amount of hDD space used, we had our PM's make a back-up of all their projects, place it in a folder named "backup(projectname)" located in the same DIR as their project.
We simply burned those to DVD, and removed the backups after we were done, nothing big. A few days later several people came to us (IT) with reports of files missing, entire directories being deleted, etc...which wasn't too significant, as I do daily backups.
After going through the logs, I realized that we had Auditing enabled, but not File Auditing. So I have no real way of knowing who is responsible for deleting them.
After realizing this, I created a testing file, gave myself permissions, and enabled full file auditing on the individual user. I went to the file on my PC, deleted a file, and added a file...and went to check the Audit logs to see if it showed up.
To my dismay, it doesn't show any log of me adding/removing any files, and I timed myself exactly, as my log is about 500 pages long, I went to the time frame, and nothing.
This folder is shared, only to three people, myself, my boss, and the admin account of the server. I setup the file auditing on my account only for testing purposes.
Appreciate the help
I am not familiar with 2k3 as much as I'd like to be, but here is my current predicament.
We run a file-share server on Server 2k3.
We are a domain network. We login at our PCs, and depending on the user and what group they're assigned to, have access to different parts of the file share server.
Recently, in an attempt to reduce the amount of hDD space used, we had our PM's make a back-up of all their projects, place it in a folder named "backup(projectname)" located in the same DIR as their project.
We simply burned those to DVD, and removed the backups after we were done, nothing big. A few days later several people came to us (IT) with reports of files missing, entire directories being deleted, etc...which wasn't too significant, as I do daily backups.
After going through the logs, I realized that we had Auditing enabled, but not File Auditing. So I have no real way of knowing who is responsible for deleting them.
After realizing this, I created a testing file, gave myself permissions, and enabled full file auditing on the individual user. I went to the file on my PC, deleted a file, and added a file...and went to check the Audit logs to see if it showed up.
To my dismay, it doesn't show any log of me adding/removing any files, and I timed myself exactly, as my log is about 500 pages long, I went to the time frame, and nothing.
This folder is shared, only to three people, myself, my boss, and the admin account of the server. I setup the file auditing on my account only for testing purposes.
Appreciate the help