- Related Products
- AD360
- Log360
- ADManager Plus
- ADSelfService Plus
- EventLog Analyzer
- Exchange Reporter Plus
Click here to expand
The ADAudit Plus agent is a lightweight Windows service that collects audit data from domain controllers, servers, and workstations. Installing the agent ensures:
Note: This guide covers the Windows agent only. For the macOS agent, go to this help page.
| Benefit | Description |
|---|---|
| Real-time data collection | Captures logon events, user activities, and AD changes immediately as they occur |
| Improved accuracy | Minimizes missed events compared to remote, agentless polling methods |
| VDI and cloud support | Works with virtual desktops, VMs, cloud-hosted endpoints, and geographically distributed machines |
| Optimized network usage | Reduces bandwidth utilization through efficient, batched data transfer |
| Lightweight | Minimal CPU, RAM, and disk usage (see Resource usage) |
| Server load reduction | Collects and parses audit data locally, reduces processing overhead on the ADAudit Plus server |
| No admin privileges needed on endpoints | The ADAudit Plus server does not need administrative privileges on endpoints |
| No RPC ports needed for data collection | Agent pushes data to the server over HTTPS—no inbo und RPC port s required on endpoints |
| Encrypted communication | All agent-to-server communication is over HTTPS |
| Scalability | Handles hundreds or thousands of endpoints efficiently |
| Offline resilience | Temporarily stores audit data locally (EventData directory) and synchronizes when connectivity is restored |
| Resource | Typical Usage |
|---|---|
| CPU | 1-2% |
| RAM | 65-75MB |
| Disk (agent installation) | ~2GB |
| Disk (EventData cache) | 2GB default (configurable up to 10GB) |
| Network | HTTPS on port 8555 (configurable) |
Copyright © 2020, ZOHO Corp. All Rights Reserved.