Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

Troubleshooting

How do you check to confirm the audit policies have been applied to the monitored workstations?

  1. Log in to any computer with domain admin credentials.
  2. Go to Start and type in "Command Prompt". Right-click Command Prompt, and select Run as administrator.
  3. Type in “gpresult /S <monitored computer> /F /H a.html”.
  4. Ensure that all the audit policy settings and security log settings are in place.

How to check if the monitored events are being logged in workstations

  1. Log in to any computer with domain admin credentials.
  2. Go to Start ;> Run. Type in "eventvwr.msc".
  3. In the Event Viewer window, right-click on the event viewer in the top-left corner and select Connect to Another Computer. In the Select Computer window that opens, check Another computer and type in the machine name whose events you want to verify. Click Browse, type in the machine name, and click OK.
  4. Click Windows Logs > Security.
  5. Right-click Security, then select Filter Current Log...
  6. Monitor the desired event ID by entering details such as event logged time or the exact event ID under the <All event ID> text box.
  7. Close the window once you’ve verified that events are being logged in your workstations.

ADAudit Plus Trusted By

A single pane of glass for complete Active Directory Auditing and Reporting