Solved

Log LDAP queries

Posted on 2014-03-07
3
423 Views
Last Modified: 2014-03-31
I would like to log all LDAP queries to a domain controller over a 24h period. What's the best approach? I'm looking for the content of the queries, not just the source.
0
Comment
Question by:albatros99
3 Comments
 

Accepted Solution

by:
eSourceONE earned 500 total points
ID: 39912621
You could use portmirroring and tools like wireshark to monitor traffic on LDAP port 389.
This will only monitor the unencrypted traffic though. If your clients / software use LDAP over SSL you will see traffic on port 636 but won't be able to see the contents.

You should also read this:
http://technet.microsoft.com/en-us/library/dd408940%28v=ws.10%29.aspx

and this:
http://technet.microsoft.com/en-us/library/cc961809.aspx

and see if you can get ADS to log the queries in the windows security logs.

Hope this helps.

Best regards,

Lars
0
 
LVL 1

Expert Comment

by:miller3773
ID: 39913802
Netmon from Microsoft will also work and you can isolate only LDAP traffic.
0
 
LVL 3

Author Comment

by:albatros99
ID: 39966525
I ended up changing the following two keys:

HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics
"15 Field Engineering" set to 5 (default is 0)
 
HKLM\System\CurrentControlSet\Services\NTDS\Parameters\
Expensive Search Results Threshold:DWORD set to 1

The information ends up in the Directory Service Log.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question