Solved

Auditing a specific account

Posted on 2003-12-12
6
402 Views
Last Modified: 2013-12-07
I have been asked to create an audit trial for an active directory user  account.

I used a specific OU and created granular GPO for full auditing applying it to that account.

However,

I would like to report activity with that account keeping the following in mind:

1. The name of that account is a subset of many others so it is hard to search for with the large quantity of events that exists in out enviorment.

2. Is there a audit reporting tool that will simplify this proccess

3. If other accounts are in need of monitoring is it a difficult proccess to maintain?

Thanks

Webaxion

0
Comment
Question by:webaxion
  • 2
  • 2
  • 2
6 Comments
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
You either need to get a third party tool that stuffs the logs into a database you can get reports out of or take a look at
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=9989D151-5C55-4BD3-A9D2-B95A15C73E92

This utility collects Event Logs in a comma-delimited text file which allows you to import them into a database for analysis
0
 

Author Comment

by:webaxion
Comment Utility
Is there a way to parse the information into a more usable report?

And can anyone point me into a direction of a 3rd party tool that will provide the reporting?

0
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
>Is there a way to parse the information into a more usable report?
If there is someone on staff familiar with databases, this should be a trivial task.
Worst case: open the file in excel and sort on desired field.

 Sawmill is popular: http://www.sawmill.net/formats/Windows_Event.html
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 37

Accepted Solution

by:
Bing CISM / CISSP earned 333 total points
Comment Utility
why dont try Crystal Reports? it is powerful and its special edition is for w2k resource kit:

Seagate Software Crystal Reports 6.0
http://www.tburke.net/info/reskittools/topics/crystal.htm

Windows NT: Monitoring Events
www.microsoft.com/technet/prodtechnol/ winntas/proddocs/concept/xcp09.asp

AFAIK, what you want can all be done well by Crystal Reports, very professional.

for more about Crystal Reports:

http://www.crystalkeen.com/articles/crystalreports/
http://www.pnltools.com/printproduct.asp?productid=34

hope it helps,
bbao
0
 

Author Comment

by:webaxion
Comment Utility
Found an application that does this and much more.

http://www.gfi.com/lanselm/

Creates a wide variety of customized reports that are just the ticket for upper management ECT.
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
Comment Utility
good, webaxion, if you think your question is finished, could you please accept helpful commnets OR ask EE moderators make it as PAQ and get refund. happy new year
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now