Solved

Auditing Windows 2008 Server access

Posted on 2012-04-07
1
280 Views
Last Modified: 2012-07-03
We have some Windows 2008 servers that multiple departments have RDP access to.

I would like to view who has been logging into these servers by using the Security logs.

Could someone tell me

i. What event id/ event id's I should be looking for in the Sec logs

ii. Is there anyway to find out the IPs that these accounts are logging in from
0
Comment
Question by:bruce_77
1 Comment
 
LVL 8

Accepted Solution

by:
teomcam earned 500 total points
ID: 37819754
If you wanna find out who logged in recently via RDP please use the following command

query session /server:YOURSERVERNAME

And if you find out that someone has logged in and then left the country, you can kick them off too - the above command will tell you each user's session id and you can use this to boot them off the box. In this example, the session id is 1.

rwinsta /server:YOURSERVERNAME 1


If you wanna know who logged in and who logged off please follow the link below.


Event IDs 538 and 540 for tracking Log on and Log off's.


In addition a useful article below
http://www.eventtracker.com/blog/2011-07-20-the-key-difference-between-%E2%80%9Caccount-logon%E2%80%9D-and-%E2%80%9Clogonlogoff%E2%80%9D-events-in-the-windows-security-log/
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now