Enabling Auditing
Thursday, November 13th, 2008Windows supports auditing of various account- and system-related events, which can be invaluable when troubleshooting a security incident. You can enable auditing of nine different types of access on a local server. You can also configure these settings via an Active Directory group policy, which overrides any local settings that you’ve defined. After auditing has been configured, audit messages are created in the Security event log.