Navigation: Monitoring with EventSentry > Compliance Tracking > File Access Tracking > Prerequisites |
In order to use file access tracking, auditing needs to be configured on the files and/or folders you would to track with EventSentry. Additionally, object tracking needs to activated either through group policy or through the local security policy.
1. Enable Object Tracking See Tracking Requirements for more information on how to enable the object tracking audit category. If object tracking is not enabled, then the necessary 560 or 4663 events will not be generated by the Operating System, even when auditing is enabled on a directory.
2. Setup Auditing for a file and/or folder Once object access tracking has been enabled, you will need to configure auditing on the directories you want to track with EventSentry. You configure auditing by accessing the folder properties in Windows explorer and accessing the advanced security properties as shown in the screenshots below:
The detailed steps to enable auditing are as follows:
Auditing entries will be effective immediately.
|