This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ARS 7.1 AD changes only as impersonate User

Hello,

When we do changes within the ARS Console, this seems to be done always with the Quest Service User.

When i check the AD Logs i only see this Name.

Is there a possibility to change this, so we see the Credentials of the User who changed it instead of the Service User?

Kind Regards, Peter

Parents
  • It's a regular Windows event log - all the standard fields plus a number of replacement strings in the Description fields. As long as your Graylog solution can ingest regular Windows event logs (EVT files), you should be fine. The only "trick" is parsing out the replacement strings (a windows event log construct) in the description of each event. This is where you will find the event details I mentioned above. If Graylog works with Windows logs, it may even offer you a tool that lets you analyze a sample windows event to help you isolate these strings so you can pull them into reports etc.
Reply
  • It's a regular Windows event log - all the standard fields plus a number of replacement strings in the Description fields. As long as your Graylog solution can ingest regular Windows event logs (EVT files), you should be fine. The only "trick" is parsing out the replacement strings (a windows event log construct) in the description of each event. This is where you will find the event details I mentioned above. If Graylog works with Windows logs, it may even offer you a tool that lets you analyze a sample windows event to help you isolate these strings so you can pull them into reports etc.
Children
No Data