IDS / Forensics Windows Event IDs.

Good Afternoon Dear EE.

Due to change in security policy, we implemented centralized log collector using Windows Server Log Subscriptions.

Can anyone point to good source of IDS / Forensics Event IDs to monitor?

We want to track what is important in Windows 2008 Domain, involving users, groups, directory services, GPOs, DNS, DHCP anything involving servers and workstations.
Also any recommendation how anyone else is monitoring it.

All feedback is greatly appreciated.
r4kietaAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

btanExec ConsultantCommented:
I like to suggest baseline aligning to the below - see section 4 for assurance and timely incident trigger cum response upon detection. Specifically the values is also as per MS best practices for
Securing AD focusing on several topics from defending against different attacks on AD installations to recommending an holistic list of events to monitor within a targeted domain.
https://www.nsa.gov/ia/_files/app/spotting_the_adversary_with_windows_event_log_monitoring.pdf

Of course ideally we wanted all security event id but it is just going to be overwhelming and most probably backfired. The above is subset of the whole security listing - below is just an example (for sharing) list for all security events in Windows 7 and in Windows Server 2008 R2. There will definitely be more for Win8 and server 2012
https://support.microsoft.com/en-us/kb/977519

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
r4kietaAuthor Commented:
Perfect thanks this is what I was looking for.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Security

From novice to tech pro — start learning today.