Auditing Security Events

An Overview of Auditing

Auditing enables you to determine which activities are occurring on your system. Through auditing, you can track access to objects, files and folders; as well as any modifications made to the objects, files and folders. Auditing therefore enables you to collect information associated with resource access and usage on your system by allowing you to audit system logon, file access, object access, as well as any configuration changes. An audit trail can be defined as a list of audit entries which portray the life span of an object, or file and folder. When an event or action takes place that's configured for auditing, the action or event is written to the security log. Security auditing events are thus written to the security log of the system, and can be accessed from Event Viewer.

Audit entries in the security log can be one of the following:

The main types of events which you should audit are listed below:

One of the primary steps in implementing auditing is to create an audit plan which would define the objectives of implementing auditing on your system. The aspects which should be included in your audit plan are:

Auditing of security event categories are disabled by default. In order to track access to objects, and files and folders, you have to define and configure an audit policy. You have to determine the types of events which you want to audit, and include the security requirements of the organization when you configure audit policies. Another step in defining audit policies is to determine the particular event categories which should be audited.

The event categories which you can audit are

For each of the above mentioned event categories, you can choose between three values when you enable auditing. These values in turn determine the condition for which an audit entry would be created:

You can define audit polices for:

Audit policies can be configured through Group Policy for the entire site, or a domain and OU. You can also configure audit policies for servers and workstations.

You can enable the Security Options policies to secure certain server components from a number of threats and accidents:

The information recorded on an event in a security event log is listed below:

A few recommendations for auditing security events are summarized below:

How to define an audit policy on the local computer

  1. Click Start, Programs, Administrative Tools, and then click Local Security Policy.
  2. Expand the Local Policies in the left pane.
  3. Click Audit Policy.
  4. The options which you can define audit policy for are listed in the right pane.
  5. Proceed to select and double-click the desired option.
  6. When the Properties dialog box for the policy which you have selected opens, enable success audit, failure audit, or both success and failure audits.
  7. Click OK.

How to define an audit policy on the domain controller

  1. Click Start, Programs, Administrative Tools, and then click Domain Controller Security Policy.
  2. Expand the appropriate nodes in the left pane to move to Computer Configuration, Windows Settings, Security Settings, Local Policies, and then Audit Policy.
  3. Click Audit Policy.
  4. Proceed to select and double-click the desired option.
  5. When the Properties dialog box for the policy which you have selected opens, enable success audit, or failure audit, or both success and failure audits.
  6. Click OK.

How to define the event categories to audit for a site, domain, or OU

  1. Click Start, Administrative Tools, and then click Active Directory Users And Computers
  2. In the left console pane, right-click the site, domain, or OU; and then select Properties from the shortcut menu.
  3. Click the Group Policy tab, add a new policy, and click Edit
  4. In the Group Policy Object Editor console, in the left console tree, expand Computer Configuration, Windows Settings, Security Settings, Local Policies and then expand Audit Policy
  5. In the details pane, right-click the particular event category which you want to audit; and then select Properties from the shortcut menu.
  6. When the Properties dialog box of the event category opens, select one or both of the following options: Success, Failure
  7. Click OK.

How to enable auditing for Active Directory objects.

  1. Open the Active Directory Users And Computers console
  2. Ensure that Advanced Features are enabled on the View menu
  3. Select the Active Directory object which you want to configure auditing for, and then select Properties on Action menu.
  4. When the Properties dialog box of the object opens, click the Security tab.
  5. Click Advanced to move to the Advanced Security Settings For dialog box for the Active Directory object.
  6. Click the Auditing tab.
  7. Click Add, and then specify the users or groups for which you want to audit object access.
  8. Click OK.
  9. When the Auditing Entry For dialog box for the object appears, choose the event(s) that you want to audit by choosing either one of, or both of the following options: Successful, Failed; alongside the particular event(s).
  10. Use the Apply Onto list box to set where the auditing should take place. The default setting is This Object And All Child Objects.
  11. Click OK.

How to enable auditing for files and folders

  1. Open Windows Explorer.
  2. Right-click the file or folder which you want to configure auditing for, and then select Properties from the shortcut menu.
  3. On the Security tab, click Advanced.
  4. Click the Auditing tab on the Advanced Security Settings For dialog box of the file or folder.
  5. Click Add, and then choose the users/groups for which you want to audit file or folder access. Click OK.
  6. In the Auditing Entry For dialog box for the file/folder, select the events that you want to audit by checking either the Successful option, Failed option, or both of these options alongside the particular event(s). You can choose to audit the following events:
    • Full Control
    • Traverse Folder/Execute File
    • List Folder/Read Data
    • Read Attributes
    • Read Extended Attributes
    • Create Files/Write Data
    • Create Folders/Append Data
    • Write Attributes
    • Write Extended Attributes
    • Delete Subfolders and Files
    • Delete
    • Read Permissions
    • Change Permissions
    • Take Ownership
  7. Use the Apply Onto list box to specify the location where auditing should occur. The default setting is This Folder, Subfolders And Files.
  8. Click OK.

How to apply an audit policy to Active Directory users and OUs using Group Policy

  1. Click Start, Run, enter mmc in the Run dialog box, and click OK.
  2. Using the File menu, click Add Snap in, and then click Add.
  3. Select the Group Policy Object Editor management tool and then click Add.
  4. When the Select Group Policy Object dialog box opens, click Browse to choose the proper GPO for the specific domain or OU.
  5. In the left pane, expand Computer Configuration, Windows Settings, Security Settings, and then expand File System to set a audit policy for the file system
  6. Right-click the File System node to add audit settings for a file/folder.
  7. Using the browse interface, locate the file/folder for which you want to configure auditing.
  8. Click Edit Security to specify the auditing settings.

How to access Event Viewer to view security log information

  1. Click Start, Programs, Administrative Tools, and then click Event Viewer

How to view information in the security log through Event Viewer

  1. Open Event Viewer
  2. In the console tree in the left pane, click Security
  3. The details pane is populated with all events that exist in the security log, together with summary information such as Date, Time, Category, Event ID, and User; on each entry.
    • A key icon is displayed alongside successful audit events.
    • A lock icon is displayed alongside unsuccessful audit events.
  4. You can double-click on an event entry to view its properties.

How to filter events in the security log

  1. Open Event Viewer
  2. In the console tree in the left pane, click Security
  3. On the View menu, click the Filter option.
  4. On the Filter tab, specify the filter criteria that you want to use to display a specific event(s) in the security log.
  5. In the Event Types section of the dialog box, specify the types of events that you want to display in the security log.
  6. In the Event Source list, choose the source that logged the event(s) which you want to display.
  7. In the Category list, choose the event category.
  8. In the Event ID box, enter the event identity number
  9. In the User box, enter the user name
  10. In the Computer box, enter the computer name.
  11. Use the From list boxes to enter the start parameters for the events which should be filtered.
  12. Use To list boxes to enter the end parameters for the events which should be filtered.
  13. Click OK to display the filtered events in the security log.
  14. Clicking the Restore Defaults button on the Filter tab removes the security log filter.

How to configure the size of the security event log

  1. Open Event Viewer
  2. In the console tree in the left pane, right-click Security and then select Properties on the shortcut menu.
  3. When the Security Properties dialog box opens, on the General tab, enter the maximum log file size. The default setting is 512 KB. You can set the maximum log file size to any size from 64 KB to 4,194,240 KB.
  4. Choose one of the following options listed beneath the When Maximum Log File Size Is Reached section of the dialog box:
    • Overwrite Events As Needed: When selected, the oldest events in the security log are replaced when new events need to be logged.
    • Overwrite Events Older Than _ Days: Enter the number of days after which the system can overwrite an event.
    • Do Not Overwrite Events (Clear Log Manually): When selected, you have chosen to manually clear the security log. The system does not overwrite or replace any events in the security log when the maximum log file size is reached. If the security log is not manually cleared, all new events are dropped, and are therefore not recorded in the security log.

How to clear the security log

  1. Open Event Viewer
  2. In the console tree in the left pane, right-click Security and then select Clear All Events on the shortcut menu.
  3. When the Event Viewer message box appears, click Yes to archive the existing entries in the security log prior to it being cleared; or click No to simply delete the existing entries in the log.
  4. If you chose to archive the entries in the security log, enter a name and a file format for the log file.
  5. Click Save.

How to archive a security log

  1. Open Event Viewer.
  2. In the console tree in the left pane, right-click Security and then select Save Log File on the shortcut menu.
  3. Enter a name for the file and then enter a file format for the file.
  4. Click Save.


Top 5 Free Networking Tools

Bookmark Auditing Security Events

Latest Blog Posts


English English GermanGerman SpanishSpanish FrenchFrench ItalianItalian PortuguesePortuguese RussianRussian DutchDutch
GreekGreek HindiHindi JapaneseJapanese KoreanKorean ChineseChinese Chinese (Simplified)Chinese (Simplified) ArabicArabic

Copyright 2009 Tech-FAQ. All rights reserved. Privacy Policy.