This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Old and new values are not displayed for ACL

Hello,

I have Change Auditor (release 6.8) auditing an ISILON, and I able to get an alert when a permission or access is changed over an SMB shared folder. 

The problem is that the report not show de old value. The value FROM is empty, so I can't know what change or what was the value before the change. Example of event reported:

Action:  Modify Attribute
From:
To:      Permission Allow (CASA\C00056) Full Control This file only Inherited Permission Allow (CASA\TAdmin) Full Control This file only Inherited Permission Allow (CASA\h03046) Full Control This file only Inherited Permission Allow (CASA\Usuarios_SI) Full Control This file only Inherited Permission Allow (CASA\DELLISILON) List Folder / Read Data + Read Attributes + Read Extended Attributes + Read Permissions This file only
Result:  Success

 

I see at https://support.quest.com/technical-documents/change-auditor-for-active-directory/6.9.1/user-guide/14#TOPIC-638044, the following note:

From | To

Displays the old value that was assigned to the object and the new value that is now assigned

NOTE: The From | To information does not apply to permission/access control list (ACL) type changes and is replaced with the Changes table. This information is also not available for occurrence type events, such as when an object is created or deleted.
 
But in spite of this, should have a way in order to know what permission was changed. The team that work with auditing, can't do they work if they not know exactly what permission was changed.
 
Many thanks for any help about this!!!