Security Compliance

Audit policies and best practices for SEM

Learn how to configure Windows Audit Policy for use with SolarWinds Security Event Manager (SEM). Windows Audit Policy determines the verbosity of Windows Security Logs on domain controllers and other computers on the domain. The recommendations in this document have been found to be most effective from both a best practice and compliance standpoint, and are based on customer experience and recommendations from Microsoft.

First published date

11/29/2018 10:33 PM

Last published date

9/22/2023 5:36 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).
Windows Audit Policy is used to determine the verbosity of Windows security logs on domain controllers and other computers on the domain. The recommendations in this document have been found to be most effective from both a best practice and compliance standpoint, and are based on customer experience and recommendations from Microsoft.

Product section

Security Event Manager

Resolution

Requirements 

Setting Windows Audit Policy for use with the SolarWinds Security Event Manager requires the following:

  • Active Directory deployed. Policies can be at the local machine if AD is not deployed.
  • Windows Server 2003 or higher.
  • Permissions to change Windows Audit Policy at the domain, site, or OU level using Group Policy Management or a similar application.
  • Access to the web-based SEM console or the Adobe-Air-based SEM console.


Windows Audit Policy Definitions 

This section is adapted from information available at:
http://technet.microsoft.com  (© 2016 Microsoft, available at http://technet.microsoft.com, obtained on December 27, 2016.)

You can find relevant articles by searching for audit policy best practice from the page linked above.

Audit account logon events

  • Logon events represent instances of users logging on to or logging off from a computer that is logging those events. Account logon events are specifically related to domain logon events and are logged in the security log for the related domain controller.

Audit account management

  • Account management events are the “change management” events on a computer. These events include all changes made to users, groups, and machines.

Audit logon events

  • Logon events represent instances of users logging on to or logging off from a computer that is logging those events. Events in this category are logged in the security log of the local computer onto which the user is logging, even when the user is actually logging onto the domain using their local computer.

Audit object access

  • Object access events track users accessing objects that have their own system access control lists. Such objects include files, folders, and printers.

Audit policy change

  • Policy change events represent instances in which local or group policy is changed. These changes include changes to user rights assignments, audit policies, and trust policies.

Audit privilege use

  • Privilege use events track users accessing objects based on their level of privilege to do so. Such objects include files, folders, printers, or any object that has its own system access control list defined.

Audit process tracking

  • Process tracking logs all instances of process, service, and program starts and stops. This can be useful to track both wanted and unwanted processes such as AV services and malicious programs, respectively.

Audit system events

  • System events include start up and shut down events on the computer logging them, along with events that affect the system’s security. These are operating system events and are only logged locally.

Windows Audit Policy Best Practice 

Windows Audit Policy is defined locally for each computer, but SolarWinds recommends using Group Policy to manage the Audit Policy at both the domain controller and domain levels.

To set Windows Audit Policy using Group Policy Object Editor:

  1. Expand Computer Configuration > Windows Settings > Security Settings > Local Policies, and then select Audit Policy in the left pane.
  2. Select the policy you want to define in the right pane, and then click Properties on the Action menu.
  3. Select or clear Success and Failure according to the instructions below.

Default Domain controllers policy 

Select Success and Failure for all policies except:

For these, only select Failure.

Default Domain Policy 

Default Domain Policy applies to all computers on your domain except your domain controllers.

For this policy, select Success and Failure for the following:

  • Audit account logon events
  • Audit account management
  • Audit logon events
  • Audit policy change
  • Audit system events

You may also select Success and Failure for Audit process tracking to monitor critical processes such as the AV service or unauthorized programs such as games or malicious executable files.

Note: Enabling auditing at the level of Audit process tracking will significantly increase the number of events in the system logs. Therefore, Your SEM database will grow more quickly as it collects these logs. Similarly, there could be bandwidth implications as well. This is wholly dependent upon your network’s traffic volume and bandwidth capacity. Since agent traffic is transmitted to the manager as a real-time “trickle” of data, bandwidth impact is typically minimal.
 

Changing from category-level auditing to sub-category auditing

With Windows 2008 and newer operating systems, Microsoft introduced sub-category auditing. Enabling auditing at the category-level will automatically enable all sub-categories. This can result in a higher than expected auditing level. Enabling the sub-category-level auditing will automatically disable the category-level auditing and allow you to fine tune the auditing. Before enabling the subcategory, we recommend setting the sub-category auditing before enabling the sub-category. We provide the PCI auditing settings as a reference, and you can adjust to meet your auditing requirements or to fulfill your auditing preferences.


Open the Group Policy Management console (or gpedit.msc if not using AD).

To change the sub-category settings:

  • Navigate to Computer-Configuration  >  Windows-Settings  >  Security-Settings  > Advanced Audit Policy Configuration

To enable the sub-category auditing (which disables the category-level auditing):

  • Navigate to Computer-Configuration  >  Windows-Settings  >  Security-Settings  >  Local-Policies  >  Security-Options  >  Audit:Force-audit-policy-subcategory-settings  ==> enabled

PCI-DSS log selection 

PCI Compliance and Security Event Manager

Category /Subcategory 

Setting 

System 

 
Security System ExtensionNo Auditing
System IntegritySuccess and Failure
IPsec DriverNo Auditing
Other System EventsNo Auditing
Security State ChangeSuccess and Failure

Logon/Logoff 

 
LogonSuccess and Failure
LogoffSuccess and Failure
Account LockoutSuccess and Failure
IPsec Main ModeNo Auditing
IPsec Quick ModeNo Auditing
IPsec Extended ModeNo Auditing
Special LogonSuccess and Failure
Other Logon/Logoff EventsSuccess and Failure
Network Policy ServerNo Auditing

Object Access 

 
File SystemSuccess and Failure
RegistrySuccess and Failure
Kernel ObjectNo Auditing
SAMNo Auditing
Certification ServicesNo Auditing
Application GeneratedNo Auditing
Handle ManipulationNo Auditing
File ShareSuccess and Failure
Filtering Platform Packet DropNo Auditing
Filtering Platform ConnectionNo Auditing
Other Object Access EventsNo Auditing
Detailed File ShareNo Auditing

Privilege Use 

 
Sensitive Privilege UseFailure
Non Sensitive Privilege UseNo Auditing
Other Privilege Use EventsNo Auditing

Detailed Tracking 

 
Process TerminationNo Auditing
DPAPI ActivityNo Auditing
RPC EventsNo Auditing
Process CreationNo Auditing

Policy Change 

 
Audit Policy ChangeSuccess and Failure
Authentication Policy ChangeSuccess and Failure
Authorization Policy ChangeSuccess and Failure
MPSSVC Rule-Level Policy ChangeNo Auditing
Filtering Platform Policy ChangeNo Auditing
Other Policy Change EventsSuccess and Failure

Account Management 

 
User Account ManagementSuccess and Failure
Computer Account ManagementSuccess and Failure
Security Group ManagementSuccess and Failure
Distribution Group ManagementSuccess and Failure
Application Group ManagementSuccess and Failure
Other Account Management EventsSuccess and Failure

DS Access 

 
Directory Service ChangesNo Auditing
Directory Service ReplicationNo Auditing
Detailed Directory Service ReplicationNo Auditing
Directory Service AccessFailure

Account Logon 

 
Kerberos Service Ticket OperationsSuccess and Failure
Other Account Logon EventsSuccess and Failure
Kerberos Authentication ServiceSuccess and Failure
Credential ValidationSuccess and Failure

Note: The above auditing includes disabling 9 of the sub-categories that create noise from Windows Filtering Platform. Not disabling this 'noise' can cause in a higher level of events being sent to the SEM, rules firing needlessly, the need for increased resource reservations in the SEM, and excessive number of events logged internally in the Windows security event log.

 

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.