Options
Question for the MS folks
Bl8ckr0uter
Inactive Imported Users Posts: 5,031 ■■■■■■■■□□
in Off-Topic
Here is the situation. I need to track a particular users logon activity (how many times a day, what time, how often and from what IP, the later is extremely important). I know this is tracked in the security log of the domain controllers but I am having trouble parcing the information in excel (since it does not show the output of the messages) and it keeps crashing my computer management (the logs are 91 mg from each of our DCs). What I am looking for is a way to parse the data in powershell (or perl*) and write the output to a file. Have any of you do anything like this?
I am going to look up perl later on today but I am basically looking for a powershell perspective.
I am going to look up perl later on today but I am basically looking for a powershell perspective.
Comments
-
Optionsrwmidl Member Posts: 807 ■■■■■■□□□□Maybe try the Event Comb feature in the Server 2003 feature pack?
List of features available in the Event Comb tool
I haven't used this tool so it may not do what you need it to, fyi.CISSP | CISM | ACSS | ACIS | MCSA:2008 | MCITP:SA | MCSE:Security | MCSA:Security | Security + | MCTS -
OptionsBl8ckr0uter Inactive Imported Users Posts: 5,031 ■■■■■■■■□□Interesting!
I also found this site so I might need to try to script it in posh first:
The PowerShell Guy : PowerShell examples used on ars technica -
Optionsrwmidl Member Posts: 807 ■■■■■■□□□□Here is the thread where I found the Filter Comb referenced:
Auditing User Logon/Logoff in Windows Server Active DirectoryCISSP | CISM | ACSS | ACIS | MCSA:2008 | MCITP:SA | MCSE:Security | MCSA:Security | Security + | MCTS -
OptionsBl8ckr0uter Inactive Imported Users Posts: 5,031 ■■■■■■■■□□Here is the thread where I found the Filter Comb referenced:
Auditing User Logon/Logoff in Windows Server Active Directory
I actually had it installed on my machine already (since it is with the 2k3 resource kit). Pretty epic tool. -
OptionsEverlife Member Posts: 253 ■■■□□□□□□□Check out LogParser from Microsoft. I haven't used it in quite a long time, but you can run very detailed queries and export the results to a CSV. They may even have added direct export to Excel. There is a learning curve, but what you're asking for is fairly basic, so I'm sure you'll be able to find some examples online.