How To: Auditing On A Per-User Basis

| | No TrackBacks
Normally, all the audit functions are system-wide; there is not much granularity; in systems with a number of users it's hard to perform  detailed audit, since there will be too many events logged. Logs can become quite resource- and time-consumed, if configured poorly.

However, starting from Windows Server 2003 SP1 a new function is available, named "Per-User Selective Audit". It means that you can override the settings for system-wide audit for a given user, thus preventing unnecessary events from being recorded.

The practical usage of this option is watching the actions of a given user you are suspicious about.

To configure and learn more about this function, run the following command in a command-line session:

auditusr /?

No TrackBacks

TrackBack URL: /blog/mt-tb.cgi/39

blog comments powered by Disqus

About this Entry

This page contains a single entry by Konstantin Boyandin published on December 16, 2009 1:41 PM.

Disabling LM Authentication was the previous entry in this blog.

A Common Misconception Regarding Security Logs is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.