Sprinkler Systems Uhaul move Lawn care Roses and trees Ford Parts Chrysler Parts Lake Powell New IPod Touch Apps New IPhone Apps IPhone Apps IPad Information IPad Apps Android APPS Android Games APPS Android Systems Android Tablets APPS and Beyond Smartphone Apps Smartphone Games Apps Repair and Tools Tablet PC Car Sharing Car Leasing Tabler Pc Fly Fishing Toyota Cars Vacation Rentals Stock market NYSE SSE Stock Freight & Shipping News Gluten Lactose Gout My Coupon Life Campgrounds Check Outdoor Kitchen Design and Redoo Bath Remodeling Palm Springs Las Vegas Vacation Tipps Lake Powell Boating Homes for lease Electric and green Car Blog Pearls and diamonds Whatsapp and forget SMS Blog, What is Whatsapp App Renovation Blog Condo for rent or lease Solar Panel Solar Energie Sun Power Blog Truck for Sale Reconstruction Blog
Computers » microsoft.public.cn.windows.server » 关于审核中的对象访问--audit object a
关于审核中的对象访问--audit object a [message #139524] Fr, 06 Januar 2006 10:28
WintersChen  
求助各位高手~~~问题如下:在一个windows2000的 环境下,如何让一台域成员服务器(2000)上 面的共享文件夹具有对访问人员(域用户访问 文件服务器的网络共享文件夹)的审核作用, 按照微软的方法如下,GPO里设置审核中的访问 事件和访问对象上启用failure的审核日志功能 然后再在共享文件夹上属性--安全--高级--审 设置相关操作。但是设置完毕并刷新全局策 后,在本地策略上看到的是
effective setting仍旧未启动“audit object access “,而且客户端对文件服务器的共享访问中的 禁止删除,写入等操作均不会在
时间察看器 中看到标题为”object access“的日志。比如event ID 560,
但是在本地机器上设置共享文件,对来访的域 用户设置审核策略,却可以正常获得审核日志 。(本地采用的XP+SP2)。
审核的日志域成员客户如下,现在需要的是在 成员文件服务器上同样获得这样的审核日志
category : Object Access

Object Open:
Object Server: Security
Object Type: File
Object Name: C:\Documents and Settings\user\Desktop\Share\New Folder\New
Text Document.txt
Handle ID: -
Operation ID: {0,6817652}
Process ID: 4
Image File Name:
Primary User Name: User$
Primary Domain: MYDC
Primary Logon ID: (0x0,0x3E7)
Client User Name: Symantec-Gateway
Client Domain: MYDC
Client Logon ID: (0x0,0x661295)
Accesses: DELETE
ReadAttributes

Privileges: -
Restricted Sid Count: 0


For more information, see Help and Support Center at
Re: еĶ--audit object access [message #141168 ] Mi, 11 Januar 2006 05:50
brayn xie  
GPMC鿴һ,Ƿ񱻶ϳе˳Ա,DzDZ ?


"Winters Chen" <WintersChen [at] discussions.microsoft.com> wrote in message
news:9CEEE540-EA10-441A-A55B-13E48D1AA0EC [at] microsoft.com...
> λ~~~£һwindows2000򻷾£ һ̨Ա2000ĹļожԷԱ ļ繲ļУã΢ķ £GPOеķ¼ͷʶfailure ־ܣȻڹļ--ȫ--߼-- ϲˢȫֲԺڱزϿ
> effective settingԾδaudit object access ҿͻ˶ļĹеĽֹɾдȲ
> ʱ쿴 пΪobject access־event ID 560,
> ڱػùļõû˲ԣȴ ־زõXP+SP2
> ˵־Աͻ,ҪԱļͬ ־
> category : Object Access
>
> Object Open:
> Object Server: Security
> Object Type: File
> Object Name: C:\Documents and Settings\user\Desktop\Share\New Folder\New
> Text Document.txt
> Handle ID: -
> Operation ID: {0,6817652}
> Process ID: 4
> Image File Name:
> Primary User Name: User$
> Primary Domain: MYDC
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: Symantec-Gateway
> Client Domain: MYDC
> Client Logon ID: (0x0,0x661295)
> Accesses: DELETE
> ReadAttributes
>
> Privileges: -
> Restricted Sid Count: 0
>
>
> For more information, see Help and Support Center at
RE: 关于审核中的对象访问--audit object [message #141170 ] Mi, 11 Januar 2006 07:05
WintersChen  
已经解决了,谢谢前辈,是域本地安全策略的 问题。

“Winters Chen”编写:

> 求助各位高手~~~问题如下:在一个windows2000的 环境下,如何让一台域成员服务器(2000)上 面的共享文件夹具有对访问人员(域用户访问 文件服务器的网络共享文件夹)的审核作用, 按照微软的方法如下,GPO里设置审核中的访问 事件和访问对象上启用failure的审核日志功能 然后再在共享文件夹上属性--安全--高级--审 设置相关操作。但是设置完毕并刷新全局策 后,在本地策略上看到的是
> effective setting仍旧未启动“audit object access “,而且客户端对文件服务器的共享访问中的 禁止删除,写入等操作均不会在
> 时间察看器 中看到标题为”object access“的日志。比如event ID 560,
> 但是在本地机器上设置共享文件,对来访的域 用户设置审核策略,却可以正常获得审核日志 。(本地采用的XP+SP2)。
> 审核的日志域成员客户如下,现在需要的是在 成员文件服务器上同样获得这样的审核日志
> category : Object Access
>
> Object Open:
> Object Server: Security
> Object Type: File
> Object Name: C:\Documents and Settings\user\Desktop\Share\New Folder\New
> Text Document.txt
> Handle ID: -
> Operation ID: {0,6817652}
> Process ID: 4
> Image File Name:
> Primary User Name: User$
> Primary Domain: MYDC
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: Symantec-Gateway
> Client Domain: MYDC
> Client Logon ID: (0x0,0x661295)
> Accesses: DELETE
> ReadAttributes
>
> Privileges: -
> Restricted Sid Count: 0
>
>
> For more information, see Help and Support Center at
Vorheriges Thema:如何停掉所有GP,因用xp windows登
Nächstes Thema:服务组件RPC为什么总是停止?
Gehe zu:
  


aktuelle Zeit: Fr Mai 25 06:28:15 CEST 2012

Insgesamt benötigte Zeit, um die Seite zu erzeugen: 0,02872 Sekunden
.:: Startseite - Hinweise - Impressum ::.

Powered