R
Ross
Hi everyone,
I'm just looking for some advice from everyone here on what kind of events
you guys audit? We have a distributed IT team and more often than not if
someone fails to follow change control proceedure then it's difficult to tell
what change has been made and the logs aren't always that useful. So my
question is what kind of things do your enterprises audit? For example,
changes to group policy. At what level? For example, 'default domain policy'
has been changed or 'this particular policy' has been changed. How do you
aggregate that information? For example, proactively through SCOM 07 or MOM
or retroactively via event manager's logs.
Thanks in advance for your suggestions.
Best wishes,
Ross.
I'm just looking for some advice from everyone here on what kind of events
you guys audit? We have a distributed IT team and more often than not if
someone fails to follow change control proceedure then it's difficult to tell
what change has been made and the logs aren't always that useful. So my
question is what kind of things do your enterprises audit? For example,
changes to group policy. At what level? For example, 'default domain policy'
has been changed or 'this particular policy' has been changed. How do you
aggregate that information? For example, proactively through SCOM 07 or MOM
or retroactively via event manager's logs.
Thanks in advance for your suggestions.
Best wishes,
Ross.