Hi,
I am trying to get the Windows Infrastructure all configured. For the most part I think I have it configured right but something are not working. I would like to collect logon/logoff logs from AD.
I follow the docs about Windows Apps Infra and put Add-ons on my Splunkforwarder ( AD domain ) etc
Domains, domain controllers, Group policy and Organizational Units are found but DNS, Users and Groups are not found.
Any help to get this working would be appreciated.
Excuse my English
Thanks
Geoffrey
I found something about logs, i use Windows Server 2012 R2 in french and dashboards on Windows Infrastructure App don't read french logs so it didn't work.
Is there a way to resolve this ?
Thanks
Geoffrey
Hi Djow,
Collecting logon/logoff from Windows is difficult because every access generates 10-12 events and there are many automatic accesses of services, so it's difficult to display the real accesses to systems.
I filtered taking
Instead to have the active sessions I used a simple script for systems greater than 2008 seven:
@echo off
REM --------------------------------------
REM Controllo delle sessioni utente attive
REM --------------------------------------
REM Get event date and time
set date_time=%date% %time%
REM Print the event date and time, this will be the event timestamp
echo Current time: %date_time%
REM print the current user session
query user
Bye.
Giuseppe
When you say "DNS, Users and Groups" are not found, what do you mean exactly by that?
Did you activate a GPO to audit Logon/Logoff events?
On the installation for Windows Infrastructure , After checking data, the App detects features to collect and then disable DNS, Users, Computers and Groups
However, on the Eventviewer on my Windows(AD controller and domain) and on Splunk research , i see the " Event ID 4624" that correspond to logon/logoff.
GPO to audit Audit account logon events, account management, logon events and Powershell are activated.