Requirements |
Top Previous Next |
The process tracking feature works by intercepting Audit Success events that are written to the security event log when Audit Process Tracking is enabled in the Local Security Policy of the monitored host. As such the following requirements exist:
Windows NT 4 From the "Administrative Tools" open "User Manager" or "User Manager for domains" and select Policies -> Audit from the menu. Then, check the "Success" checkbox next to "Process Tracking".
Windows 2000 (and higher) without Active Directory Open "Local Security Policy" in the "Administrative Tools". Navigate to "Security Settings" -> "Local Policies" -> "Audit Policy". Double-click "Audit process tracking" and check the "Success" checkbox. This change might take several minutes until it becomes effective.
Windows 2000 (and higher) with Active Directory Open the appropriate group policy or open the "Domain Security Policy". There, navigate to "Audit Policy" and set "Audit process tracking" to "Success". Depending on your Active Directory setup you might need to edit a group policy other than the Domain Security Policy.
You can change the "Log size" settings by opening up "Event Viewer" (from Administrative Tools) and right-clicking "Security Log". Select "Properties" from the menu and verify that the "Log size" is correctly set to "Overwrite events as needed". Also verify that the "Maximum log size" is sufficiently big.
|