ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    File Auditing

    IT Discussion
    6
    9
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BRRABillB
      BRRABill
      last edited by

      I was wondering if anyone is doing file auditing, and what they were using for it. (Locally on a Windows 10 machine.)

      I have a need to watch a few folders and get simple reports on who accessed what files, and potentially what they did to them. (I know this is really two separate tasks.)

      I know this is possible from the OS itself, but I've always found doing this through Event Viewer (or even a program like Splunk) a little tedious.

      I also know there are programs out there to do this, but often these are very, very expensive.

      So as always, I am sure there is either a way I am missing, or some great idea/program ML has that will accomplish this. Or just tell me to suck it up and use Event Viewer. 🙂

      1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender
        last edited by

        Sounds like a good use of ELK.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          Yup, sounds like an itch waiting for ELK to scratch it. Or Logg.ly if you are using them.

          BRRABillB 1 Reply Last reply Reply Quote 0
          • BRRABillB
            BRRABill
            last edited by

            Well, I could use Splunk as well.

            I admittedly was looking for something "easy" ... plug and play, so to speak.

            But I guess I find myself at the intersection of ease and cost.

            1 Reply Last reply Reply Quote 2
            • DustinB3403D
              DustinB3403
              last edited by

              Did @scottalanmiller make a guide on how to setup ELK and getting logging started?

              travisdh1T scottalanmillerS 2 Replies Last reply Reply Quote 0
              • BRRABillB
                BRRABill @scottalanmiller
                last edited by

                @scottalanmiller said in File Auditing:

                Yup, sounds like an itch waiting for ELK to scratch it. Or Logg.ly if you are using them.

                BTW: I gave up on piping XS to Logg.ly. I found a bug in their software, and it appears it is only fixed in the paid version.

                They wanted me to trial the paid version and test, but I had already moved it to Splunk.

                I'll go back and do the testing for them though, in a few days,

                1 Reply Last reply Reply Quote 0
                • travisdh1T
                  travisdh1 @DustinB3403
                  last edited by

                  @DustinB3403 said in File Auditing:

                  Did @scottalanmiller make a guide on how to setup ELK and getting logging started?

                  It's still waiting for the last part... the bit that sends the logs to the server. If I had actually set it up before myself I'd finish it, but alas, it's an rsyslog world for me.

                  1 Reply Last reply Reply Quote 0
                  • J
                    joelbarlow40
                    last edited by joelbarlow40

                    Please follow the instructions mentioned in th below techNet articles and apply the same to track all activities : http://blogs.technet.com/b/mspfe/archive/2013/08/27/auditing-file-access-on-file-servers.aspx

                    Apply or Modify Auditing Policy Settings for a Local File or Folder
                    https://technet.microsoft.com/en-us/library/cc771070.aspx

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @DustinB3403
                      last edited by

                      @DustinB3403 said in File Auditing:

                      Did @scottalanmiller make a guide on how to setup ELK and getting logging started?

                      I did. It's on here somewhere 🙂

                      I prefer Graylog in most cases, though. It's come a long way.

                      1 Reply Last reply Reply Quote 1
                      • 1 / 1
                      • First post
                        Last post