Configuring your first audit path

Configure your first audit path to start collecting file access activity with FileAudit.

Published January 28, 2026

Before you begin

FileAudit must be installed and you must be able to open the FileAudit console.

Configuring a path switches on Windows auditing behind the scenes, so FileAudit needs administrator rights on the machine that hosts the folder. FileAudit uses them to enable the Windows Audit Object Access policy and to deploy the NTFS audit settings (SACL) on the folder, at steps 6 to 8 below.

An audit path is a single file or folder you ask FileAudit to watch. Once a path is configured, FileAudit records who accessed it, when, and how, and stores every event in its database.

In this example you will audit a test folder named C:\FileAudit-Test. Create it first if it does not already exist.

At each step of the wizard you can let FileAudit apply a setting automatically or handle it yourself. For your first path, accept the automatic option at every step. It is the recommended configuration and the fastest way to a working audit.

Add a Windows path to audit

  1. Open the FileAudit console.

  2. Go to Windows paths.

  3. Click on Add a path.

    Add a path



  4. Select the path C:\FileAudit-Test.

  5. Click on Next and keep the default audit settings.
    Please note that FileAudit will automatically enable the required Windows auditing settings.

    File / folder audit configuration wizard



  6. Select whether FileAudit should automatically enable the "Windows Audit Object Access" policy or assume it is already configured.

    Enable the object access audit



  7. Select whether FileAudit should automatically configure NTFS auditing (SACL deployment) on the file or folder, or assume it is already configured.

    Configure the NTFS audit on the file/folder



  8. Choose how NTFS audit inheritance is handled by FileAudit.

    Enable the inheritance of the NTFS Audit settings

  9. The folder host will be added to the ‘Licensed servers’ list.

    FileAudit path wizard License

  10. Enable real-time event monitoring.

    Schedule FileAudit for this server


  11. Your path is now configured. It appears in the Windows paths list, and FileAudit records every access event on C:\FileAudit-Test and stores it in its database.


Note

💡 Tip: A path can be added by right-clicking a file or folder in Windows Explorer and selecting FileAudit from the context menu, or entered manually using filters in reporting views.

Next step

Continue the scenario in Displaying the events to open the All access events report and see the activity FileAudit is now recording on C:\FileAudit-Test.