Windows Server Auditing
Date: 10/21/05
(IT Professionals) Keywords: no keywords
I have a need to audit a bunch of servers at my office.
We need to monitor these kinds of changes:
* Registry
* Event Logs
* Active Directory Changes
An example of what we're looking for is "who disabled the network card?" and "who disabled this person's account"
We don't need instant monitoring, we just need to be able to go back "after the fact" and see what one our network operations guys did.
I know we may need a few utilities to pull this off, and we have maybe 5-6 servers we want it on.
What do you guys use for this?
Thanks!
Source: http://community.livejournal.com/itprofessionals/27185.html