Ga naar hoofdinhoud

Active Directory

Monitors Active Directory and alerts when issues arise.

notitie

Overview

This event monitor actively tracks and alerts on changes within Active Directory, including new, modified, and deleted users and computers. It also monitors for locked-out, expired, or disabled user accounts and changes in specified AD groups.

info

Use Cases

  • Daily Administration: Stay updated on Active Directory changes during routine system management.
  • Security Monitoring: Quickly detect and respond to locked-out accounts.

Distinguished Name

Specify the distinguished name for the base of the Active Directory search. For example, for monitoring in the pim.local domain, enter DC=pim,DC=local.

Connectivity

Set the alert level for when the event monitor cannot contact your network device.

Monitoring Options

User Account Alerts

Alert TypeDescription
CreationAlert with [Success/Info/Warning/Error/Critical] if new user accounts are created.
ModificationAlert with [Success/Info/Warning/Error/Critical] if user accounts are modified.
DeletionAlert with [Success/Info/Warning/Error/Critical] if user accounts are deleted.
LockoutAlert with [Success/Info/Warning/Error/Critical] if user accounts are locked out.
InactivityAlert with [Success/Info/Warning/Error/Critical] if user accounts have not logged in for [#] days.
ExpirationAlert with [Success/Info/Warning/Error/Critical] if user accounts have expired.
DisabledAlert with [Success/Info/Warning/Error/Critical] if user accounts are disabled.

Group Specific Alerts

Alert TypeDescription
AdditionAlert with [Success/Info/Warning/Error/Critical] if members or computers are added to the group.
ModificationAlert with [Success/Info/Warning/Error/Critical] if group members or computers are modified.
RemovalAlert with [Success/Info/Warning/Error/Critical] if group members or computers are removed.

Filter Options

  • Group Focus: Limit alerts to specific groups.
  • Ignore Specific Users: Exclude specific user accounts from monitoring. Use commas to separate values.
  • Ignore Conditions: Options to ignore disabled user accounts, contact objects, or accounts that have never logged in.

Group Membership Check

Specify the group name for exclusive monitoring and alerts on membership changes.

Authentication and Security

Ensure the account used for authentication has the necessary permissions for searching through Users and Computers sections of Active Directory, as well as group membership if applicable.

Protocols

Data Points

This event monitor generates a variety of data points, including:

  • Sample Output (to be detailed further as needed)
Data PointDescription
Detected ComputersThe total number of computers detected by the event monitor.
Deleted UsersThe number of deleted users as found by the event monitor's last run.
Disabled AccountsThe number of disabled accounts present.
Event Monitor Success/FailureThe event monitor's success state or failure state.
Expired AccountsThe number of expired accounts present.
Locked Out AccountsThe number of locked out accounts present.
Modified AccountsThe number of accounts that have been modified.
Modified ComputersThe number of computers that have been modified.
Modified MembersThe number of members that have been modified.
New ComputersThe number of new computers added.
New UsersThe number of new users added.
Removed UsersThe number of removed users.
Stale AccountsThe number of stale accounts detected.
Users AddedThe total number of users added.

Sample Output

Sample Output