I am trying to track file access for files that are located in a SAN, and events logged by Windows do not show a drive letter? Is this supported?

Article ID: 194
Category: File Access Tracking
Created: 2011-04-08

Under some circumstances, Windows will log file names with a path to the device object (e.g. \Device\Harddiskvolume3\file.txt) instead of the path to a logical drive (e.g. E:\file.txt).

When adding directories to the list of tracked directories in "File Access Tracking", simply specify the path using the device object name (as shown in Windows security events (e.g. 560/567 or 4663)) and file access tracking will work as usual.



Try EventSentry on-premise

FREE 30-day evaluation

Download Now