I have PA Server Monitor 6.2.0.221 and would like to create an Event Monitor on our Domain Controller that will monitor the security log for a specific account logon ( account is member of Domain Admins)

I have set the event monitor for Microsoft_Windows_Security_Auditing for Event ID 4672 and "usersname" then write to a text file. This text file is huge and I need to be able to limit contents.

Is there an Event ID or Logon Type I can add that will just let me know when this user logs on to any Server in our domain?

Thanks for any assistance!

asked 23 Nov '16, 14:51

techgal64's gravatar image

techgal64
521611
accept rate: 28%


Hi techgal64,

There are many different event ids that you can monitor for. Here is a link to a Microsoft page that talks about some of them and a link to our documentaion on how to filter for them. Hope this helps.

Description of security events in Windows Vista and in Windows Server 2008

How to Audit Windows Logons and Logon Failures

Thanks
Quinn

Please make sure to mark your questions accepted when you have your answer by clicking the gray check mark to the left of the answer.

link

answered 23 Nov '16, 15:05

Quinn's gravatar image

Quinn ♦♦
14.1k3925
accept rate: 37%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×12
×4
×3
×3

Asked: 23 Nov '16, 14:51

Seen: 1,876 times

Last updated: 23 Nov '16, 15:05