Registrations to Open-AudIT forums are now closed. To ask any new questions please visit Opmantek Community Questions.

Open-AudIT

What's on your network?
It is currently Wed Apr 17, 2024 5:44 am

All times are UTC + 10 hours




Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 
Author Message
PostPosted: Sun Nov 23, 2008 11:01 pm 
Offline
Helper

Joined: Fri Nov 16, 2007 1:32 am
Posts: 73
Location: Dallas,Texas
I was thinking about working on this this week but figured I would share in case anyone else was interested and wanted to try.

Windows provides event log triggers(xp,2003+) for when certain event id's occur.


I thought of this as a quick monitoring solution.
1) Event triggers are created through GPO or whatever other method.
2) When the event trigger is kicked off do to an event id specified. It will run audittrigger.vbs locally or on the network. Event Triggers will pass the event id and the description to the vbs.
3) VBS will simply format the passed information and upload it using msxml to the openaudit server.

Then create a front page query that actively shows the information based on latest to oldest. And wham you have monitoring.

_________________
1400 Servers Audited (1 hour interval) Applied via a local scheduler, deployed via GPO.
Running OA on IIS6 Web Server
90% Windows 2k3 Server (std,ent)
5% Windows XP
5% Windows 2000


Top
 Profile  
Reply with quote  
PostPosted: Fri Jan 23, 2009 7:04 pm 
Offline
Helper

Joined: Wed Sep 05, 2007 1:43 am
Posts: 55
Can your post some example?


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 

All times are UTC + 10 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group