Writing logs to a write-only location
Boss Everyware can write the delimiter-separated log files (.dsv, .csv) to a write-only location. This prevents users from reading and removing log files.
The monitored users must have the following permissions applied to the log folder, subfolders and files:
- Read Attributes
- Read Extended Attributes
- Create Files / Write Data
- Create Folders / Append Data
- Write Attributes
- Write Extended Attributes
If the folder is shared, the Change share permission must also be set.
If you are unfamiliar with changing the permissions, here is a step-by-step example. Experiment only with the folders that you have created!
We will set the write-only permissions for the Users group to the folder named WriteOnlyFolder:
1. Open the folder's Security properties, select the Users group and click Advanced:

2. In the Advanced Security Settings box, unselect the Inherit from parent... checkbox:

3. Click Copy in the Security dialog:

4. Now select the entry Users which is applied to This folder, subfolders and files, then click Edit:

5. Set the permissions as shown below:

6. Click OK three times.
7. If the folder is shared to get logs from other computers, switch to the Sharing tab, click Permissions and ensure the Users have Change permissions to the share:

8. Configure the loggers to write into the prepared folder:

See also:
What are the log files?
How to control creation of the log files?
|