Documentation forSecurity Event Manager

Enable Windows file auditing for use with SEM

Enable file auditing in Windows to monitor events related to users accessing, modifying, and deleting sensitive files and folders on your network.

To maximize the value of this type of auditing, enable auditing on a file server where you installed a SEM agent, and only for the specific files and folders you want to monitor. If you enable auditing on all files or folders, the additional auditing may impact SEM performance.

Complete the procedures below to enable object auditing on your server, and then enable file auditing on the files and folders that you want to audit. If Windows is logging the events and your server is running a SEM agent, the SEM console will begin displaying the new file auditing alerts.

File auditing is only available on systems running Windows Server with Desktop Experience. If you installed Windows Server with Server Core on your system, file auditing is not available.

Enable object auditing in Windows

  1. In the Windows Control Panel, navigate to Administrative Tools > Local Security Policy.
  2. In the left pane, expand Local Policies, and then click Audit Policy in the left.
  3. Select Audit object access in the right pane, and then click Action > Properties.
  4. Select Success and Failure, and then click OK.
  5. Close the Local Security Policy window.

Enable file auditing on a file or folder in Windows

  1. In Windows Explorer, locate the file or folder you want to audit.
  2. Right-click the file or folder, and then select Properties.
  3. Click the Security tab.
  4. Click Advanced.
  5. Click the Auditing tab.
  6. Click Add. (If using Windows Server 2008, click Edit.)
  7. Enter the name of a user or group you want to audit for the selected file or folder, and then click Check Names to validate your entry. For example, enter Everyone.
  8. Click OK.
  9. Select Success and Failure next to full control to audit everything for the selected file or folder.
  10. Optionally, clear Success and Failure for unwanted events such as:
    • Read attributes
    • Read extended attributes
    • Write extended attributes
    • Read permissions
  11. Click OK in each window until you are back at Windows Explorer.
  12. Repeat these steps for all files or folders you want to audit.