Audit RDP connections on domain members from... Expand / Collapse
Author
Message
Posted 12/17/2013 3:22:14 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 12/17/2013 3:11:25 AM
Posts: 1, Visits: 0
Hello,

I would like to know if it is possible to audit RDP connections on Windows 2008 servers (in the domain) directly from tha AD security event log.

We have installed en agent on the AD to collect security events and would like to avoid installing it on all servers.

I was expecting to see a "4624" event with "Logon Type: 10" in the AD events but I did not.

I am interesting to audit the user computer/ip, username, server connected to.

Do you know if this is possible?

Am I missing some audit settings?

TIA for your support
Michaël
Post #1300
Posted 12/22/2013 4:18:29 PM
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 201, Visits: 0
The 4624 Event ID with the Type 10 Logon should exist on the server that was logged on to. I would expect that you would only see these logs if you were collecting logs from the host that you wanted to audit.
Post #1302
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 9:30pm