|
Lesson 1
Creating a Baseline for Member Servers
9-5
When you configure Windows Server 2003 to audit events, the system creates
entries
in the Security log that you can see in the Event Viewer console (see Figure
9-3). Each
audit entry contains the action that triggered the event, the user and
computer objects
involved, and the event’s date and time.
f09pm03
Figure 9-3
The Event Viewer console
A GPO’s audit policies are located in the Group Policy Object Editor console
in the
Computer Configuration\Windows Settings\Security Settings\Local
Policies\Audit
Policy container, as shown in Figure 9-4. Each policy creates an audit entry
in
response to the following events:
f09pm04
Figure 9-4
The Audit Policy container in the Group Policy Object Editor console
|