Ad Widget

Collapse

Windows AD: Audit password changes

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • charly1986
    Junior Member
    • Oct 2023
    • 3

    #1

    Windows AD: Audit password changes

    Hello everyone,

    I'm trying the template "template_windows_ad_event_log_(2008_r2-2012_r2)" for monitoring the password changes in an AD domain, but it doesn't work when applied as is to a Windows DC Server, which has auditing enabled. Do I need to modify something in the template for it to work?
    The server has the Zabbix agent for Windows installed. Does it work that way, os is it through another protocol?

    I'd also appreciate it if someone knows of another template for auditing that data.

    Thanks
  • Viktors Fomics
    Member
    • Oct 2025
    • 42

    #2
    Hello

    Zabbix agent should be used, but here it isn't exactly clear what exactly doesn't work for you. I mean, if no data is received at all, could it be that the Agent doesn't have the permissions to read the event log? The agent should run as Local System (or another account with explicit Security log access).

    Comment

    • Viktors Fomics
      Member
      • Oct 2025
      • 42

      #3
      Additionally, it could be just that the hostname should be adjusted - if the default setting of 'Hostname=Zabbix server' is left, then the server won’t associate the incoming active data with the correct host, hostname should be the actual DC server's hostname.

      Comment

      Working...