Quantcast
Channel: Support Portal
Viewing all 484 articles
Browse latest View live

computer report last logged in

$
0
0

Morning

Is there a report or a way of creating a report that allows us to see when a computer was last logged in?

We have a lot of computers in our AD and want to tidy them up.

Cheers


Wayne


Re : The event log file is corrupted - Error Code:5dc

$
0
0
Hello,

It is a rare scenario where the event log corruption occurs while fetching events from a NetApp Filer. It could be due to one of the following reasons,
  1. Event Log service already has an open handle to the *.evt file 
  2. Some event log fields are missing, E.g. "Computer name" or "Source"
  3. Network adapter drivers
The closer reason would be point 2 and it should get resolved on subsequent event collections. You can try opening the security log file (stored in the location configured under Evt File storage path) using event viewer and observe the result. You may also try rebooting ADAudit Plus server. If the issue persists, please send an email to support@adauditplus.com so that we would engage in a remote session.

Regards
ADAudit Plus Team

Re : Connecting to install on server

$
0
0
Hello,

Yes, It is possible to connect to ADAudit Plus console from your client. Please follow steps given below,

1. Login to ADAudit Plus server
2. Stop ADAudit Plus (You may find an icon in system tray if it's running, so right click -> Stop)
3. Open Command prompt (Run as Administrator)
4. Navigate to the <Installation folder>\bin E.g. C:\Program Files>x86>\ManageEngine\ADAudit Plus\bin
5. Execute the below command
      InstallNTService.bat
6. This would install NT Service for ADAudit Plus
7. Go to Services.msc and locate " ManageEngine ADAudit Plus Service "
8. Right Click -> Properties -> Logon tab and make sure to provide proper credentials to run the service.
9. Start ADAudit Plus service

Hope this helps.

Regards
ADAudit Plus Team

Re : computer report last logged in

$
0
0
Hello,

You may make use of following reports in ADAudit Plus which would give you the desired results.

1. Last logon on Workstations 
2. Users First and Last logon by Computers

Hope this helps. 

Regards,
ADAudit Plus Team

Re : computer report last logged in

Re : Connecting to install on server

ADAudit Plus monitor iSCSI on File Server

$
0
0

Morning

I am trying to setup the File Servers in our ADAudit Plus and when I go to the server it cannot see the share.  We think this is because the data share is in fact a presented iSCSI volume.  Do this mean that we need to create a share on the told level of the presented drive on the file server in order to allow the software to audit it?

Wayne

How to create custom report for specific security events related to logons

$
0
0
I am new to the product and have not found what I'm looking for as a predefined report.

I'm looking to report on successful non-interactive logons. Event 4624 with logon type not equal to 2.

Also looking for events 4648 (attempt to logon with explicit creds), 4775 (account not mapped), and 4777 (DC failed to validate creds)

I have attempted to define custom reports but they all turn out empty.

Can someone point me in a good direction?


Re : ADAudit Plus monitor iSCSI on File Server

$
0
0
Hello,

First of all, shares on an iSCSI volume connected through Windows servers can be monitored in ADAudit Plus. Major possibilities for the mentioned issue are listed below,

1. Insufficient privileges to the account used by ADAudit Plus to view the shares
2. ADAudit Plus uses flat name of the server to get shares and in most of the DFS environments, it would be either the DFS root name or the FQDN

In first case, please ensure the ADAudit Plus service runs with proper privileges on File server. The next scenario can be bypassed through a flat entry in DNS which points to the FQDN of the server.

Moreover, you may try accessing the shares from ADAudit Plus server and make the change depending on how it works. 

Regards,
ADAudit Plus Team

Create report for specific field on user account

$
0
0
New to AD Audit Plus and still learning.

I am trying to create a report to show me all changes to one specific field on a user account, ProxyAddresses but it isn't working or I am not doing it correctly.

Can someone assist with how to setup a report for one specific field on an AD account please?

PolicyStatusLogon failure: unknown user name or bad password - Error Code:8007052e

$
0
0

I am a first time user and have added my domain and a domain controller.  I have the yellow exclamation saying "Configure "Default Domain Controllers Policy" to enable auditing events for domain : XXXX click here" 

I click there and the following error comes up:

PolicyStatusLogon failure: unknown user name or bad password - Error Code:8007052e

I have followed the steps to configure it manually, which all settings were already set.  The domain user is correct and not locked out.

I am using Build Number: 4.6.0 | 4662

Re : How to create custom report for specific security events related to logons

$
0
0
Hello,

First of all, please ensure that you are running the latest build (4662). If not, upgrade the software by applying appropriate service pack(s) from following link,


Note: Please follow the instructions given in the link thoroughly while applying the service pack

Once you are in 4662 build, please follow the steps given below,

1. Go to Reports tab
2. Click on Custom Reports located at right top of the console 
3. Create Custom report
4. Provide a name, description and desired report type
5. Select : Local Logon/Logoff category
6. Under Sub module "Local Logon Success ", check all except "Interactive Logon success"
7. Click next ( You would be taken to the next page with summary of previous actions
8. select desired columns to be viewed
9. Save the Report

Note: You may schedule the same report  on the fly using "Scheduler " option

Hope this helps. 

Regards,
ADAudit Plus Team

Re : Create report for specific field on user account

Re : PolicyStatusLogon failure: unknown user name or bad password - Error Code:8007052e

$
0
0
Hello,

Please ensure the product runs as service with proper privileges. If not, follow the steps given below to install NT service.

1. Go to Services.msc
2. Locate ManageEngine ADAudit Plus Service, If not found, proceed with step 4
3. If it's available, make sure to provide proper privilege to run the service (provide admin account)
4. Open command prompt (Run as Administrator)
5. Navigate to <Installation folder>\bin
6. Execute the command , InstallNTService.bat
7. Now you would be able to locate ManageEngine ADAudit Plus service. 
8. Most importantly the account provided in the service should have enough privileges to configure policies through GPO

Hope this helps. 

Regards,
ADAudit Plus Team

Re : PolicyStatusLogon failure: unknown user name or bad password - Error Code:8007052e


Where can I find the new feature: Search activities based on username.

Re : Where can I find the new feature: Search activities based on username.

$
0
0
Hello,

Please follow below steps to make use of the new feature "Search by Username"

1. Login to ADAudit Plus web console.
2. You may find an option at right top corner of the page says " Search by Username "
3. Please enter a username which would show you all activities in which the user is accounted for.

We are working on document updation that would be done at the earliest. 

Hope this helps. 

Regards,
ADAudit Plus Team

Re : Where can I find the new feature: Search activities based on username.

$
0
0
Thank you sir, I was blind!
Regards

Re : Use real SSL certificate for ADAudit website?

$
0
0
Any updates on a process for this? Seems like you have documentation for this with ADManager, ADSelf-Service. Would be nice to see a technical document on it.

Re : Use real SSL certificate for ADAudit website?

Viewing all 484 articles
Browse latest View live