?
Solved

How to enable audit and viewand monitor  the RDP users to the server

Posted on 2014-02-24
8
Medium Priority
?
401 Views
Last Modified: 2014-05-26
I need to audit who access the server using the Remote Desktop Protocol. I want to see from which PC/IP and what time they connected. How can I enable this in windows 2008 and 2012 server. I have AD 2008 R2.
0
Comment
Question by:jobby1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 13

Accepted Solution

by:
Alex Green earned 400 total points
ID: 39882248
ObserveIT is pretty decent

http://www.observeit.com/
0
 
LVL 12

Assisted Solution

by:ibrahim52
ibrahim52 earned 800 total points
ID: 39882259
You should visit the link below to have a better idea. Also, to be really honest FREE solution isn't there at all unless you are ready to stick with windows built-in feature of logs system which isn't good filtered.

Referred link :-
http://serverfault.com/questions/206085/are-there-any-rdp-activity-logs-windows-server-2008-r2
0
 
LVL 7

Assisted Solution

by:peea
peea earned 800 total points
ID: 39882294
> I want to see from which PC/IP and what time they connected.

This info can be available from firwall logs. Has the 2008 sever enabled logging on the LAN adapter?
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 12

Assisted Solution

by:ibrahim52
ibrahim52 earned 800 total points
ID: 39882914
in fact this info is also available in EVENT logs regarding who accessed the server what time and from which IP.
0
 
LVL 7

Assisted Solution

by:peea
peea earned 800 total points
ID: 39887552
One benefits of checking syslog or other firewall logs similar to syslog is for search ability. You can't simply do a full-text search aganist Windows Event Logs.

Windows Event Logs does provide some kind of searching fucntion: filter, but it however does not support full-text search and you have to deal with multple GUI fields for a simple search.
0
 

Author Comment

by:jobby1
ID: 39910650
How can I enable the auditing for RDP logins.
0
 
LVL 7

Expert Comment

by:peea
ID: 40091843
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question