Top
Systemwalker Desktop Keeper User's Guide for Administrator
FUJITSU Software

8.2.19 File Operation Log

This is the log of file operations and folder operations in the following drives that are performed in the client (CT):

Note

Functions may be restricted due to the environment being used

When setting the policy, functions may be restricted due to the environment being used.
For details, refer to "1.2.29 File Operation Log".

Set policy for collection

Set policy in the Terminal Initial Settings window or the window after the Management Console is started (CT policy settings window).

For details about the configuration value, refer to "2.4.1.2 File Operation" and "2.4.1.3 Extension".

Displayed content

The following log content can be viewed:

Name: name of the client (CT)

Occurrence Date and Time: time for collecting logs at client (CT)

User ID: the following information is displayed.

Domain Name: the following information is displayed.

Type: File Operation (fixed value)

Classification: normal

Attachment: (not displayed)

Content: for details, refer to "Collected operation logs".

Example of Content:

Operation: [Rename], Source file name:[C:\Documents and Settings\Administrator\Desktop\New Microsoft Excel Worksheet.xls], Type of drive: [Fixed], Target file name: [C:\Documents and Settings\Administrator\Desktop\List of Customer Information.xls], Type of target drive: [Fixed], Program name: [Explorer.exe]

Note: the following information is displayed:

When performing keyword search in Log Viewer, numerals can be specified as keyword.
0 to 2147483647 can be specified.
Example:
When "0123" is specified in search condition, logs with "size (byte): 201,235" displayed in notes will be searched. Logs with "size (byte): 123" displayed in notes cannot be searched.

Also, when performing a keyword search in Log Viewer, and a keyword including any of the following operation types is specified, logs for which the operation type applies may be searched.
(Applicable operation types: "View", "Update", "Create", "Delete", "Copy", "Move", "Rename", "Save As")
Example:
When a single keyword such as "copy, source file name:G:\" is specified in the search criteria, and an "OR" search is selected, logs of the "Copy" operation type will also be searched regardless of the file name for which the operation was performed. To perform a search where the operation type is "Copy" and the file name includes "G:\", specify multiple keywords with an AND condition.

Collected operation logs

The following describes the logs collected when operating files and folders on the local drive and network drive in the client (CT) where file operation log policy has been set.

Note

The following software and commands are described

When running the following software or commands, operation logs displayed in the following table will be collected:

  • Explorer (Note 1)

  • Notepad (Note 1)

  • Tablet (Note 1)

  • Microsoft(R) Word (2003, 2007, 2010 and 2013) (Note 2)

  • Microsoft(R) Excel (2003, 2007, 2010 and 2013) (Note 2)

  • Microsoft(R) PowerPoint(R) (2003, 2007, 2010 and 2013) (Note 2)

  • Command in command prompt (COPY, XCOPY, MOVE, DEL, ERASE, RD, REN, MD) (Note 1)

Note 1: Does not collect "Save as" operation logs.

Note 2: In case of Windows Vista(R), Windows Server(R) 2008, Windows(R) 7, Windows(R) 8 or Windows Server(R) 2012, only 2003, 2007, 2010 and 2013 are supported.
"Save as" operation logs can only be collected in versions 2007, 2010 and 2013.

However, be aware of the following points:

  • "Update" operation of Microsoft(R) Word will be collected as Create log.

  • Like Explorer and XCOPY, in File operation, View log of the process that has been registered as Get Operations Apart from Viewing will not be collected.

  • Even if the software and commands above are used, redundant logs may be collected.

  • When using software and commands other than the above ones, operation logs not corresponding to the actual operation (eg, "Copy" and "Cut" logs cannot be collected, but they can be collected as View, Create, Delete or Rename logs) may be collected.

  • When the "Move" operation is performed in the above software or commands, "Copy" and "Create" (move source) logs may be collected.

  • When using the redirection command (> or >>) and MD command in command prompt, logs may not be output.

When operating file and folder in the client (CT), the types of logs collected are as follows.

Log Type

Content Display of Log Viewer

View

Operation: View, File name: (Note 1), Type of drive: (Note 2), Program name: (Note 5)

Update

Operation: Update, File name: (Note 1), Type of drive: (Note 2), Program name: (Note 5)

Create

Operation: Create, File name: (Note 1), Type of drive: (Note 2), Program name: (Note 5)

Delete

Operation: Delete, File name: (Note 1), Type of drive: (Note 2), Program name: (Note 5)

Copy

Operation: Copy, Source file name: (Note 1), Type of drive: (Note 2), Target file name: (Note 3), Type of target drive: (Note 4), Program name: (Notes5)

Cut

Operation: Cut, Source File Name: (Note 1), Type of drive: (Drive 2), Target file name: (Note 3), Type of target drive: (Note 4), Program name: (Note 5)

Rename

Operation: Rename, Source File Name: (Note 1), Type of drive: (Note 2), Target file name: (Note 3), Type of target drive: (Note 4), Program name: (Note 5)

Save as

Operation: Save as, Source file name: (Note 1), Source drive type: (Note 2). Target file name: (Note 3), Target drive type: (Note 4), Program name: (Note 5)

Note 1: The name of the file or folder in the local drive is described in full path, the name of the file or folder in the network drive is described with UNC or UNC and the machine name part is the IP address

Note 2: Type of source drive

Note 3: The name of the file or folder in the local drive is described in full path, the name of the file or folder in the network drive is described by UNC or UNC and the machine name part is the IP address
The name of the file of folder is described in full path in the following cases:

Note 4: Type of target drive

Note 5: Name of the application that performs the operation

Conditions for log collection

Under what kind of conditions and operations the above "log type" can be collected is displayed as follows:

Condition

File and Folder Operations

View

Update

Create

Delete

Copy

Cut

Rename

Save as

File Operation

Log for files

In the same drive (Note 1)

View

(Note 3)

Update

(Note 3)

Create

Delete

Copy

Rename
(Cut)

Rename

Save as

In the same drive
(Note 2)

-

-

-

-

Copy

Cut

-

Save as

Folder Operation

Log for files under a folder

In the same drive (Note 1)

-

-

-

Delete

Copy

x(Note 4)
(Cut)

-

-

Between different drives
(Note 2)

-

-

-

-

Copy

Cut

-

-

Log for folders

In the same drive (Note 1)

-

-

Create

Delete

Create
(x)

Rename
(Rename)
(Delete)

Rename

-

Between different drives
(Note 2)

-

-

-

-

Create
(x)

Create
Delete
(Delete)

-

-

-: Operation is not possible.

x: Operation log cannot be collected.

View/update/create/delete/copy/cut/rename/Save as: indicates the type of collected operation log.

(): indicates the type of the collected operation file when files or folders with the same name exist in copying target or moving target. When there is no ( ), the type of recorded log will be collected.

Note 1: Operations in the same local drive or network drive. For example, see following case:

  • Operation from C drive to C drive in the local drive

  • Operation in the network drive "\\dtk\common\"

Note 2: Operations between different local drives, between the local drive and network drive or between different network drives. For example, see the following case:

  • Operations from C drive to D drive in the local drive

  • Operations between the local drive and network drive.

  • Operations from the network drive "\\dtk\common\" to the network drive "\\dtk\com\"

Note 3: Viewing of file properties in Explorer and command prompt is not a log target.

Note 4: When the folder name of the moving source is the same as that of the moving target, Rename log is collected only for files existing in the moving source folder but not in the moving target folder.

The meaning of the above table and the output logs are illustrated as follows:

Example 1:

When viewing files in the same local drive, logs displayed in View of type of log above are collected.

The window for viewing logs in Log Viewer is displayed as follows. Logs collected in this case are shown in the frame part.

The content displayed in the Content column in the frame of the above window is as follows:

Operation: [View], File name: [D:\report.doc], Type of drive: [Fixed], Program name: [winword.exe] 

This indicates that file "report.doc" in D disk root directory is viewed through Word.

Example 2:

When copying files in the same local drive, no matter whether files with the same name exist in the directory of copy target, log displayed in Copy of the above log type will be collected.

Log displayed in the Content column of Log Viewer is as follows:

Operation: [Copy], Source File Name: [D:\report.doc], Type of drive: [Fixed], Target file name: [D:\tmp\report.doc], Type of Target Drive: [Fixed], Program name: [Explorer.exe] 

This indicates that file "report.doc" in the root directory of D drive is copied to "D:\tmp" through Explorer.

Example 3:

When moving an empty folder from the local drive to a different drive and there is no folder with the same name in the moving target, two logs displayed in Delete and Create of the above log type are collected.

Log displayed in the Content column of Log Viewer is as follows:

Operation: [Create], Folder Name: [D:\log], Type of drive: [Fixed], Program name: [Explorer.exe] 
Operation: [Delete], File name: [C:\log], Type of drive: [Fixed], Program name: [Explorer.exe] 

This indicates that folder "log" in the root directory of C drive is moved to the root directory of D drive through Explorer.

Example 4:

When moving an empty folder from the local drive to a different drive and there is folder with the same name in the moving target, log displayed in Delete of the above log type is collected.

Log displayed in the Content column of Log Viewer is as follows:

Operation: [Delete], File name: [C:\log], Type of drive: [Fixed], Program name: [Explorer.exe] 

This indicates that folder "log" in the root directory of C drive is moved to a different drive through Explorer and there is folder with the same name in moving targets.

Example 5:

When viewing files in the same network drive, log displayed in View of the above log type is collected.

Log displayed in the Content column of Log Viewer is as follows:

Operation: [View], File name: [\\dtk\common\report.doc], Type of drive: [Remote], Program name: [winword.exe]

This indicates that file "report.doc" in Shared Folder "common" under the root directory of machine "dtk" is viewed through Word.