19 Replies Latest reply on Sep 17, 2014 1:19 PM by nicole pauls Branched to a new discussion.

    file audit nt authority




      I just rolled out SLEM 6.0 (and updated the agents) and turned on the new FIM feature.  In theory this is an awesome thing to have, but it's proving to be useless to me at the moment.


      Every single file audit that I have going only references NT AUTHORITY\SYSTEM as the user that is accessing any file.  This includes me local and remote (SMB) to the server.


      It's actually not even showing my access or modification of a file / folder in hand.


      I submitted a ticket with no response yet, was curious to know if anyone here has seen the issue themselves.