pelegk1 Posted November 17, 2011 Posted November 17, 2011 1) how can i write to a log, or using the system log to check when a user loged in/out from rdp?2)is there a way to monitor, if a user changed a file and when, and if he stoped/started a service?10X:)
Tripredacus Posted November 17, 2011 Posted November 17, 2011 I'm not sure about the second one, but in either case without knowing the exact configuration of your network (you provided generics) the responses you get may not be applicable to your particular setup. As far as #1 here is what I would do.Have all users who are allowed to use RDP put into the Remote Desktop Users group or a custom OU. Then I would create an Audit Policy to log authentication responses for that group. They would then show up (at least) in the Security section of Event Viewer.
pelegk1 Posted November 17, 2011 Author Posted November 17, 2011 i have a windows 2008r2 server, that is not a part of a domain!
Tripredacus Posted November 17, 2011 Posted November 17, 2011 Ok but those users still need to have accounts added to your server in order for them to work with RDP. You can still add those accounts into an OU or the Remote Desktop Users group....
allen2 Posted November 18, 2011 Posted November 18, 2011 On windows 2008R2, default security settings will already log in the eventlogs what you need.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now