Configuring policy query audit logging with dsconfig
Steps
-
Enable the file-based Policy Query Logger.
dsconfig set-log-publisher-prop --publisher-name "Policy Query Logger" --set enabled:true -
Use the
dsconfig set-log-publisher-propcommand with the following arguments:dsconfig set-log-publisher-prop --publisher-name "Policy Query Logger" --set include-query-permutations:true