Solved

Log LDAP queries

Posted on 2014-03-07
3
421 Views
Last Modified: 2014-03-31
I would like to log all LDAP queries to a domain controller over a 24h period. What's the best approach? I'm looking for the content of the queries, not just the source.
0
Comment
Question by:albatros99
3 Comments
 

Accepted Solution

by:
eSourceONE earned 500 total points
ID: 39912621
You could use portmirroring and tools like wireshark to monitor traffic on LDAP port 389.
This will only monitor the unencrypted traffic though. If your clients / software use LDAP over SSL you will see traffic on port 636 but won't be able to see the contents.

You should also read this:
http://technet.microsoft.com/en-us/library/dd408940%28v=ws.10%29.aspx

and this:
http://technet.microsoft.com/en-us/library/cc961809.aspx

and see if you can get ADS to log the queries in the windows security logs.

Hope this helps.

Best regards,

Lars
0
 
LVL 1

Expert Comment

by:miller3773
ID: 39913802
Netmon from Microsoft will also work and you can isolate only LDAP traffic.
0
 
LVL 3

Author Comment

by:albatros99
ID: 39966525
I ended up changing the following two keys:

HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics
"15 Field Engineering" set to 5 (default is 0)
 
HKLM\System\CurrentControlSet\Services\NTDS\Parameters\
Expensive Search Results Threshold:DWORD set to 1

The information ends up in the Directory Service Log.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

774 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question