Link to home
Create AccountLog in
Networking

Networking

--

Questions

--

Followers

Top Experts

Avatar of new_to_networks
new_to_networks🇺🇸

Logon / Logoff GPO not working
Need to see all log off and log on activity in the domain. So I made a GPO following these instructons:

http://social.technet.microsoft.com/wiki/contents/articles/20422.record-logon-logoff-activities-on-domain-servers-and-workstations-using-group-policy.aspx

Ran a GPUpdate.exe /force

One logon csv showed up with one entry for someone logging onto that server (not me). Nothing else since. I linked the GPO to the whole domain in which there are many, many users logging on and off different computers and servers. Why is it "stuck"? And why isn't the log off one even working?  Any help is much appreciated.

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of zalazarzalazar

It might be that it's related to "User Group Policy loopback processing mode"
Please see also:
http://social.technet.microsoft.com/wiki/contents/articles/2548.windows-server-understand-user-group-policy-loopback-processing-mode.aspx
Do you have set this policy ?
It should be set to "Replace".

Avatar of SeanSean🇺🇸

I wouldn't use the shared folder, i would copy it into the GPO's shared folder which is what pops up when you click the browse button when creating the login/logoff GPO. This way you will be sure to have the correct permissions. As zalazar said it could be the gpo loopbacking processing as well.

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Ok I went in and set User Group Policy loopback processing mode to "replace" under computer configuration. Ran the force command. Right now I have the permissions on that folder set to everyone and shared with everyone trying to get it to work. The folder is right there on that same server.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Ok its now working for users logging on and off of that server. But the GPO is linked to the whole domain and this domain controller is in no way specified. Why are those other logins and logoffs not coming in?

Avatar of SeanSean🇺🇸

Group Policy does not update the second you make a change to the policy. Replication can take up to 90 minutes. A computer checks GPO every 90 min at random times so the servers are not hit all at once. Let things replicate and then check it. Or do the gpupdate /force on the PCs by hand and check if its working.

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

I've done the force on other servers and some machines here. It only seems to record the logon and logoffs on that domain controller where I did the GPO only.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

When I run GP Results wizard on other servers for my user name- it says that GPO is applied. Its not under Denied or anything. Not showing up in the csvs at all.

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Not even working at all now. That server has stopped recording the logon and logoffs.

Avatar of SeanSean🇺🇸

From the other server try to open the csv file and edit and save it by using the share name just to be 100% sure your permissions are correct.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Yeah I can do that ok. I don't think things aren't collecting to the DC right. Under status and then Status Details, then GPOs it says:  Data is uncollected. It says:  no infrastructure Status exists for this domain. When I click Detect Now I'm getting:

A processing error occurred collecting data using this base domain controller. Please change the base domain controller and try again.

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

I've opened up a new question because of other stuff related to this here:

https://www.experts-exchange.com/questions/28303682/Can't-change-FSMO-holder-in-ADSI-Edit.html

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Ok made some changes (in other posting) and now the Status tab is working in GP Management. It shows that everything is replicating ok- but nothing is happening. The log on/offs only appear for that original DC I set it up on. Its weird because nowhere is that server specified in the GPO- it applies to the whole domain and applies to everyone. When I run the results wizard against myself on another DC- its shows the policy being applied to me, but my log on log off is not going to the csvs. The share is totally shared and everyone has permission to it- I don't know what's preventing the tons of log on log offs from getting to those csvs...

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Does anyone have any recommendations for log on log off auditing software that I could get that would pull from the whole domain?

Does anyone have any recommendations for log on log off auditing software that I could get that would pull from the whole domain?

Yes try there , one is a free ware and the other is paid one . If it is only at the case all should be in a AD and a part of the domain.

Click here for freeware and for  paid tool.

Thanks

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Yeah it seems like those run off of active directory, and believe it or not, it doesn't record log off events, only log on.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Ok then it can be as i also cross checked and it was log off details only the you need to go for the paid tool of AD as they would be only perfect to handle your query.

Thanks and try the paid one

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

I tried the paid version but still no log off capability was included. I told them that their software details said that it was included and this is how they responded:

"Sorry for the trouble you faced, we are releasing the upgraded version of the software in the next month in which we are providing the log off user detail as well. Till then if you have any other query related to our software you can ask to us.
Thanks & Regards"

So, still left in the lurch.

ASKER CERTIFIED SOLUTION
Avatar of Kevin HaysKevin Hays🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Avatar of new_to_networksnew_to_networks🇺🇸

ASKER

Thanks, I'm super busy right now, it will take me a bit to get to this and set it up. I will let you know asap.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of gheistgheist🇧🇪

You can forward events to central server.
Networking

Networking

--

Questions

--

Followers

Top Experts

Networking is the process of connecting computing devices, peripherals and terminals together through a system that uses wiring, cabling or radio waves that enable their users to communicate, share information and interact over distances. Often associated are issues regarding operating systems, hardware and equipment, cloud and virtual networking, protocols, architecture, storage and management.