Windows Auditing to Monitor File or Folder Changes
Article # 3040239 - Page views: 105
Issue
How to use Windows Auditing to determine which user, group, or program made changes to a file or folder
Cause
Windows Auditing is a feature built into Windows that can be used to monitor access to a file or folder over a long period of time with very little overhead. When Windows Auditing detects that the file or folder has been accessed, it writes an event to the Event Viewer Security log.
Solution
To turn on Windows Auditing:
- Run
secpol.msc
to open the Local Security Policy Management Console - If a User Access Control (UAC) prompt appears, Click
Continue
. If prompted for an administrator password or confirmation, type the password or provide confirmation. - In the left pane, double-click
Local Policies
, and selectAudit Policy
. - Double-click
Audit object access
. - Check the
Success
andFailure
check boxes, and clickOK
.
To allow Windows Auditing to monitor which user, group, or program made changes to a file or folder:
- Right-click the file for folder that will be monitored, and click
Properties
. - Select the
Security
tab |Advanced
|Auditing
tab. - If a User Access Control (UAC) prompt appears, Click
Continue
. If prompted for an administrator password or confirmation, type the password or provide confirmation. - Click
Add
. - In the Enter the object name to select box, add the
Everyone
group. - Click
OK
in each of the four open dialog boxes. - Check the check boxes for
Create Files/Write Data
andCreate Folders/
Append
Data
- Click OK.
Level of Complexity
Moderate
Applies to
Product | Version | Build | Environment | Hardware |
---|---|---|---|---|
Kofax VRS | 5.2 5.1.2 5.1.1 5.1 |
ALL | ALL | N/A |
Kofax Express | 3.3 3.2 3.1 |
ALL | ALL | N/A |
Kofax Capture | 11.1 11.0 10.2 10.1 10.0 |
ALL | ALL | N/A |