Ad Widget

Collapse

Monitorování RDP loginů a ZeroLogon na Windows serverrech

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • georgeMyName
    Junior Member
    • Oct 2020
    • 13

    #1

    Monitorování RDP loginů a ZeroLogon na Windows serverrech

    Ahoj, je nějaká možnost sbírat data o RDP pomocí windows agenta? Našel jsem zde řešení pomocí powershell scriptu viz. https://www.zabbix.com/forum/zabbix-...ssion-username . Máte tip ještě na jiné řešení? Stejně tak by se mi líbilo získat informaci o pokusech navázat komunikaci přes nezabezpečený netlogon. Měly by to asi být eventy 5827 - 5831. A dík za fórum
  • gofree
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2017
    • 400

    #2
    ahoj,

    pre eventlogy na windows je item key eventlog[name,<regexp>,<severity>,<source>,<eventid>,<maxli nes>,<mode>]





    pre RDP ake data ? zvycajne to vzdy konci pri poweshell skripte a userparameroch so vsetkymi plusmi a minusmi , ktore zabbix ma pri zbere logov ( nie je to primarne log collector )
    Last edited by gofree; 26-10-2020, 10:51.

    Comment

    • hermanekt
      Member
      Zabbix Certified Trainer
      Zabbix Certified SpecialistZabbix Certified Professional
      • Aug 2019
      • 59

      #3
      Ahoj,

      mrkni sem, mozna ti to pomuze. Umi to hromadu veci
      The Zabbix Team has collected all official Zabbix monitoring templates and integrations.


      Tom

      Comment

      • MichalWe
        Junior Member
        • Oct 2020
        • 1

        #4
        Ahoj,

        Pokud nechceš používat externí skripty, stačí jak píše výše gofree využít eventlog - eventlog[Security,"Logon Type:\s*10",,,^(4624|4625)$,,skip] a přes preprocesing regexem z toho dostaneš account name (?!.*\$)Account Name:\s*(\w+). Zkoušel jsem z toho regexem dostat i workstation, IP - a přesto že test prošel správně, při zpravování to házelo chyby

        MW

        Comment

        • Jasonil
          Junior Member
          • Oct 2020
          • 1

          #5

          Hello everyone,

          Quick question: I created a scheduled task that listens for the event id 4624 and does the following actions:

          1st - Runs a script to get the last event id 4624 available and puts it on %TEMP%/info.txt

          2nd - Sends a e-mail to me with the attachment "info.txt" with the last login attempt

          It works as expected, except scheduled task STARTS the actions one after another, it doesn't wait for the first action to end before the next action starts so the attachment that I get in the email is from the previous successful login and not the last one because the script probably hasn't finished when the email gets sent
          Any idea how I can force the second action to wait for the first action to have finished? Or do I have to make another scheduled task and connect the two? Fly AlaskasWorld
          Last edited by Jasonil; 31-10-2020, 06:50.

          Comment

          Working...