2012 Server. Auditpol command and "Audit policy" GPO


good evening. there windows 2012 server file server (hyper-v vm, joined in domain). wanted turn "audit object access" track file deletions. created group policy dc relevant policy , set security filtering policy applies file server. configured auditing @ folder want track. after gpupdate saw @ event viewer, security log, had stopped record various "audit success" , "audit failure" events logged before gpupdate. erased group policy , run gpupdate no result. having exported virtual machine month ago, imported offline , started looking. in local gpedit.msc had nothing configured audit policy , advanced audit policy configuration. unconfigured. running auditpol.exe / / category: * pulled several categories enabled, while running same command on live server unconfigured. run auditpol / backup in offline , auditpol / restore live , settings restored. security log began record again. activating gpo dc again settings lost again , security log stopped again.

the questions have are:

  • if local gpo has nothing configured, results of auditpol.exe / / category: * come from, having configuration settings?
  • why activating gpo dc lost settings auditing (running auditpol.exe / / category: * ) , not configured;
  • eventually auditing defined? gpo or auditpol command each category want?

thank answers.

at first, please share steps have applied enable auditing on gpo ?

before starting anything, refer on technet kb explains : how audit setting merged group policy.

here depth information advanced security auditing @ https://technet.microsoft.com/en-us/library/ff182311%28v=ws.10%29.aspx#bkmk_4

hope, helps understand concern while applying auditing policy in gpo.

moreover, when need enable auditing on object level access , track changes real time, may check lepide auditor suite appropriate solution you.


lepide - simplifying management



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2