File auditing for MOVED files.

K

Kelly Armitage

We have a Windows 2003 domain controller and have enabled auditing on our
public shares to track when (and who) has deleted any files. It works great
and logs it accordingly on the DC security events. The problem is that if
someone were to just MOVE the files (because they have the applicable
persmissions) it does not log anything. This seems like a giant loophole to
me and I am assuming I am missing something. Is there any way I can use
security/file auditing to track when someone has moved a file? I do not see
that as one of the listed options from the security/advanced/auditing tab.

Any help or suggestions welcome... thank you in advance.
 
Back
Top Bottom