Follow these steps to use Audit File Share:
-
Open Local Security Policy by clicking the Start button, typing secpol.msc into the search box, and then clicking secpol. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
-
In the left pane, expand the Advanced Audit Policy Configuration folder. Expand System Audit Policies - Local Group. Double-click on Object Access.
In the right pane double-click on Audit File Share.
- In the Audit File Share Properties window select the Configure the following events: check box. Then select the Success check box and the Failure check box to audit both successful and unsuccessful attempts to access a shared folder. Then click OK.