Jump to content

Recommended Posts

Posted
bah set it all up but cannot get an email to send... the event seems to trigger and run but im not receiving any mail.... im sure ive got the send connector configured in the mailserver as other services send email from this fileserver (fsrm etc)
Posted

aha figured it out :p)

 

I had made an anon relay, but as the task was executing under a user account, i had to give that user permission on the send connector.

 

OK so go this working on a test event, now to get it sorted for NTFS permissions...

 

Thanks for the help RabbieBurns. And for nephilim for making me persevere in my research by saying its possible. Midnight on the dot. Thankyou and goodnight.

Posted
Ive just done a gpupdate /force... Auditign was already enabled for a couple of other things.. What services do i need to start / restart? Does it really require a reboot of the server?
Posted

Ive got it sending mail from other events, I tested with some generic events that were happening all the time. So ive got the mailing part sorted..

 

I just cant seem to get these audits to log in the event viewer :(

Posted

setting what?

 

The way ive done it is to right click on an Event and enable email of that particualar event..

 

There are thousands of events I just want ntfs permissions changes email notifications :)

 

If I can get these events to appear in the log, i can just right click on it and enable email notifications..

Posted (edited)
If you're still playing with this I would use this Windows 2008 - Audit folder permissions change on folders (and/or http://www.windowsitpro.com/article/permissions/auditing-permission-changes-on-a-folder) applied through a group policy for the machine hosting the folder in question. I'd then use Windows 2008/R2 scheduled tasks which can be set to trigger on a group policy event and use that to fire off the email and if you want the contents of the event: Getting event log contents by email on an event log trigger - John Howard - Senior Program Manager in the Hyper-V team at Microsoft - Site Home - TechNet Blogs Edited by SYNACK
  • Thanks 1
Posted (edited)

Im struggling to understand step 4 of this, what is Auto Hidden Files?

 

To enable folder permission auditing, you can follow the below steps:

 

1. Click start and run "secpol.msc" without quotes.

2. Open the Local Policies\Audit Policy

3. Enable the Audit object access for "Success" and "Failure".

4. Go to Auto Hidden files and folders, right click the folder and select properties.

5. Go to Security Page and click Advanced.

6. Click Auditing and Edit.

7. Click add, type everyone in the Select User, Computer, or Group.

8. Choose Apply onto: This folder, subfolders and files.

9. Tick on the box “Change permissions”

10. Click OK.

 

Apart from that, I have done all those steps. However the only event logs I seem to be getting are 5145 but none of the expected Task Category of File System

Edited by RabbieBurns
Posted

The auditing stuff is in two parts, once you have switched it on in GPO for that system then you must go to the folder itsel an in its properties under the Security > Advanced > Auditing tab you want to add groups to the folder which are audited and what they are audited for.

 

Once both of these things are setup it should work.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...