多奇 IT 部落格

記錄著多奇數位在工作中對資訊技術的心得筆記

我們公司在替客戶做教育訓練時,有學員提出來的問題,覺得挺有趣的,分享出來給大家。

在event logs中,一般直覺的想法是,如果設定了一個條件,在觸發條件之後,都會記錄下來。但是為什麼使用上,連續觸發事件時,只會有一筆event logs,比如說:設定quota 至85mb時會發生event logs,我準備了一個90mb的檔案,連續嘗試存取寫入該設定後的資料夾,但是只會有一筆記錄的產生? 如此一來,我如何知道此使用者到底想要非法存取該資料夾幾次?

原來,是在系統預設值中,60分鐘之內只會掃瞄一次,僅管在多次的錯誤存取,只會列出一個event log出來。下表是各種 notifications 的預設時間:

通知執行限制時間間隔
電子郵件60分
事件記錄檔60分
命令60分
報告60分

這是設計上為了 disk performance 效能上的考量而設定的,如果設定太短的時間會讓 disk 太過忙碌。

2011-03-07_084044 

檢查指令為:filescrn admin options

2011-03-07_084335

修改指令為:filescrn admin options /runlimitinterval:E,6

(E: 代表EVENT , A: 代表EMAIL , C: 代表COMMAND , R: 代表報告)

留言與評論

Nikolaus Service Köln

Köln besuchen http://www.nikolausservice.com

Nikolaus Service Köln

Internet Marketing

I loved as much as you'll receive carried out right here. The sketch is tasteful, your authored subject matter stylish. nonetheless, you command get got an edginess over that you wish be delivering the following. unwell unquestionably come further formerly again since exactly the same nearly a lot often inside case you shield this increase.

Internet Marketing

Cool blogs of 2013

I have been checking out a few of your stories and i can claim nice stuff. I will surely bookmark your blog.

Cool blogs of 2013

Hi Bloggers

Hi there, I found your blog by means of Google at the same time as searching for a comparable matter, your website came up, it looks good. I have bookmarked it in my google bookmarks.

Hi Bloggers

Hi Bloggers

Super-Duper website! I am loving it!! Will come back again. I am bookmarking your feeds also.

Hi Bloggers

本篇文章的留言功能已關閉!