You can monitor the operations of an Online Responder by logging events to the Windows security event log. The Online Responder allows the configuration of the following audit events:

You must have Manage Online Responder permissions on the server hosting the Online Responder to complete this procedure. For more information about administering a public key infrastructure (PKI), see Implement Role-Based Administration.

To enable auditing of Online Responder operations
  1. Open the Online Responder snap-in, and select the Online Responder.

  2. Click Responder Properties on the Action menu, or click Responder Properties in the Action pane.

  3. Click the Audit tab, select the Online Responder audit options that you want to have logged, and then click OK.

Audit events will be logged to the Windows security log only if the Audit object access policy is enabled.

You must be an administrator on the server hosting the Online Responder to complete this procedure. For more information about administering a PKI, see Implement Role-Based Administration.

To enable the Audit object access policy
  1. Open the Local Group Policy Editor.

  2. Under Computer Configuration, expand Windows Settings, Security Settings, and Local Policies, and then click Audit Policy.

  3. Double-click the Audit object access policy.

  4. Select the Success and Failure check boxes, and click OK.

Additional references