domain controller logon / logoff user audit logs

smanif1 21 Reputation points
2020-09-17T12:30:52.817+00:00

Hi,

we have 20 domain controllers and need to forward audit logs (user logon / logoff ) to syslog server.

Below are the query.

  1. whether the audit log will get sync between all the domain controller ?
  2. what is best practice to send audit logs to sys log, all event logs from domain controller need to send separately or is there any other method.

Regards,
Mani

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,431 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,807 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,326 Reputation points Microsoft Vendor
    2020-09-18T04:19:20.853+00:00

    Hi,
    1, Based on my research, Audit logs will not get sync between all the DCs. DCs just log the events for themself.
    2, For send audit logs to system log, you can refer to the following link: https://social.technet.microsoft.com/Forums/ie/en-US/66587a55-2883-4365-be7d-ab5baed50dc0/need-to-collect-security-logs-from-all-domain-controller-to-central-location?forum=winserverDS

    Best Regards,

    2 people found this answer helpful.

  2. Falcon IT Services 226 Reputation points
    2020-09-23T03:13:00.67+00:00

    Hello Smanif,

    Aside from what's mentioned already, the Windows Event Trap Translator will also do the trick if you have SNMP. Simply locate the EVENT ID(s) you want to trap and it will send an SNMP alert every time the EVENT ID is triggered.

    https://www.falconitservices.com/support/KB/Lists/Posts/Post.aspx?ID=275

    Cheers,

    Miguel Fra
    www.falconitservices.com

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.