Had to do this recently and wanted to minimize the noise, turned on auditing for failure only and added a new ACE to the directory with only one entry, deny delete for everyone. Might not work for all situations but if you are trying to catch the mysterious disappearing files that none of the users or developers are deleting it works great. You know, those files that disappear all by themselves? J
From: James Winzenz [mailto:[email protected]] Sent: Wednesday, July 15, 2009 1:25 PM To: NT System Admin Issues Subject: RE: Who deleted files Be careful of what you turn on with auditing - you can really add clutter to the event logs if you just enable everything. You will also have to enable audit object access in the audit policy as well as configuring auditing on the folder(s) in question. From: Robert LeBlanc [mailto:[email protected]] Sent: Wednesday, July 15, 2009 9:47 AM To: NT System Admin Issues Subject: RE: Who deleted files Snookered is right I do not have auditing on but will turn it on. Never had this issue but now I know why it's there. I have my suspicions on the user only because they were called out on a bunch of non work related things being done during the work day, but no concrete evidence.. From: James Rankin [mailto:[email protected]] Sent: Wednesday, July 15, 2009 10:27 AM To: NT System Admin Issues Subject: Re: Who deleted files Unless you have file auditing turned on, I believe you're kinda snookered. Anyone with the Delete privilege is a suspect 2009/7/15 Robert LeBlanc <[email protected]> Hi all, Is there an easy way to see who deleted files from a networks drive. I've been able to restore the files from backup but we'd like to know who deleted initially. The server is Win2K. Thanks, Robert Robert LeBlanc Network Administrator MCP,MCSE Anesthesia Associates of New Mexico, P.C. (P)505-260-4300 (F)505-260-4338 (E)[email protected] ************************************************************************ ******************** ************************************************************************ ******************** Please note that the information contained in this message may be privileged and confidential and protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us by replying to the message and deleting it from your computer. Thank you. Anesthesia Associates of New Mexico, P.C. -- "On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question." http://raythestray.blogspot.com ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
