This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

FIM - File Integrity Monitoring is only showing NT/Authority

I have the latest version of SEM. And I am running a Windows Server 2019 with file shares

When my users open a file from their own desktop, It flagging as NT/Authority.

How do I fix this?

Thanks

-Garen

Parents
  • Hello Garen,  If you want to get more information on who is access the file you must make sure that the logging options are enabled either group policy edit on your AD or change the local policy on the server to enable the access details.  

    Typically these are found in windows security event logs for the details you want.

    Look for file auditing on server for a more step by step instructions,

Reply
  • Hello Garen,  If you want to get more information on who is access the file you must make sure that the logging options are enabled either group policy edit on your AD or change the local policy on the server to enable the access details.  

    Typically these are found in windows security event logs for the details you want.

    Look for file auditing on server for a more step by step instructions,

Children
  • I am having the same issue as the OP. I dont understand why FIM even exists if you cannot tell who is opening the files. So, just to clarify, you are saying that to actually see who is accessing the files you need to not use FIM and configure object auditing in group policy and then set up the auditing on the files you want and then use SEM to monitor the security event logs?. Seems pointless in having FIM! not having a go at you at all but makes the FIM connector useless. I mean, sure, its nice to know if someone changes some important files on the OS but what good is it if you cannot see who has done it? I am running this on the mail file share (but using the local drive version as I am monitoring the actual file server itself) and all the users who access files through the file share get registered as NT\Authority.