The RPC server is unavailable - Error Code:6ba
When trying to add a print server. Looked around the forum for this I checked https://www.manageengine.com/products/eventlog/help/eventlog-misc/eventlog-tips.html and I ran a test on port 135 and it shows it is open. I can open the event manager from the ADAUDIT machine of another computer just fine. I can ping the print server just fine. Everything else seem to be working ok. Any other suggestions? ============================================= Starting portqry.exe -n 127.0.0.1 -e 135 -p TCP ...
File Audit Actions - EMC
I am wondering if anyone has setup or built a File Move File Audit Action for EMC within ADAudit Plus?
The remote procedure control fail error 6ba 6be
Hi team, I'm configuring ADAP, when I do I capture events generates this error: And only happens with Windows Server 2012. I already checked on these forums and did the recommendations proposed her but still does not work me. https://forums.manageengine.com/topic/the-rpc-server-is-unavailable-error-code-6ba-after-update https://forums.manageengine.com/topic/rpc-server-unavailable-error-code-6ba
Print management monitoring
Can ADAudit plus report on the user that deleted a printer on a server? TIA!
Time a user is active on a PC during the day
Hi Guys, Does anyone know if it is possible to get a report whuch shows the total time a user is logged onto their machine each day, where their computer is unlocked (ie in an active state) I am getting requests to find out how much time users are spending at their machines activly working, and at the moment i need to manually look at the Login times each day, and remove any time i can see between a user locking and unlocking their PC during that login interval. thanks
error conllecting netapp event File : error code 8 insuficent space
Hi, From AD AUDIT, not possible to collecting audit event file I have an error code 8. Thanks Nicolas
ManageEngine ADAudit Plus 4.6.0 Build Number: 4662 Released
Dear All, Greetings from ManageEngine ADAudit Plus! ADAudit Plus latest build 4662 brings feature enhancements and issue fixes for a more thorough auditing. With ADAudit Plus, enhance your Windows Server environment auditing: [ Active Directory , Workstation Logon / Logoff , File Servers, Member Servers , EMC , NetApp Filers , FIM , Printers & USB ] to meet the most-needed security, audit and SOX, HIPAA, GLBA, FISMA & PCI-DSS Compliance demands. Enhancements and fixes in this release File
Error when initializing mssql database
Hey all, So, I'm trying to setup ADAudit Plus in our environment but am running into some trouble. I've setup a server 2008 R2 to run the application. Installed ADAudit and everything looked fine. Installed as a Windows service and tried starting it with a domain admin account. That worked just fine and the system could grab data from our DCs. The problem arises when I try to switch to using MSSQL 2008 R2 Standard as the backend database. After running the ChangeDB.bat and successfully connecting
Cannot access after upgrade
We have applied Adaudit 4.6 build 4661 and after that we cannot access to Adaudit. In the login page we receive the following error: Exception occured while validating account : No rows found for the table AaaAccountStatus in this DataObject And the page redirect to the following page http://server_name:8081/j_security_check Thanks in advance.
User report showing security groups the user is member of?
With ADAuditPlus is it possible to run a report based on users showing what security groups they are currently a member of?
File Integrity solution available in AD Audit plus
Hi Please let us know is File Integrity solution available in AD Audit plus. Thanks & Regards Vaishali Karnataki
MS SQL database migration
I'm trying to migrate from the mysql database to a Microsoft SQL database, I've been trying to do so by following the guide here , but I can't seem to get passed the first part, backing up the mysql data. I stopped the service by executing the shutdown.bat file, and waited for it to be shutdown before executing migratesqldata.bat. Whenever the latter is executed, I get the following error: ================================ERROR = *'AES_DECRYPT' is not a recognized built -in function name.* ERROR =
ADAudit Plus - Alert when >100 files modifed or created in 1 hour or less
We would like ADauditPlus to alert us when a user changes or creates multiple files in a short amount of time - like maybe 100 in an hour or so. Is this possible? This will tell us if we have a "Rogue User" on our hands. Thanks!
ADAudit Plus - HTTP Status 400 - Invalid path /home was requested
After no apparent significant change on the server, logging in from a remote host through the web interface returns: HTTP Status 400 - Invalid path /home was requested The app is running on Windows 2012 R2, 4GB RAM, 200GB disk, no disk space issue, RAM and CPU utilization are fine. Anyone have an idea what might have happened? Logging in while logged into the server itself works. Jim
Mail Server Settings, Use Secure Connections(SSL/TLS) dropdown is blank
See attached screenshot. The Use Secure Connections(SSL/TLS) dropdown is blank, and I need to choose either SSL or TLS for my office365 settings. Any help greatly appreciated! --Brian
RPC server unavailable Error Code 6ba
Hi All, I am getting this RPC server unavailable Error Code 6ba error on some of my domain controllers. I have removed the domain, and re-added it but still getting the same error. I have used the DMZ port scanner, and all ports are open to the different domain controllers. Tony.
The RPC server is unavailable - Error Code:6ba After update
I just updated to 4661 and now AD Audit is unable to connect to my domain controllers. When I go into Domain Settings and tell it to discover Domain Controllers, it says "Domain Controllers cannot be discovered" When I try to manually add them, it says they already exist and it will not let me save my settings. When I go to http://localhost:8081/runQuery.do and run select * from adsmdcconfiguration it says " The RPC server is unavailable - Error Code:6ba." I have rules in the domain controller
Real time?
I upgraded to the latest version and I see a lot of "real time" in the release notes. However I don't see where I can configure this. In domain settings, I still see x minute intervals. Email alerts and scheduled reports all still have scheduled run times. What exactly has changed, and how do I enable real-time auditing?
ADAudit Plus Fixes and Enhancements [Version 4.6.0 (4600 - 4650)]
View ADAudit Plus Latest Fixes and Enhancements Version 4.6.0 (4650) Build - July 2014: *New : Real time auditing for Domain Controllers [Optional]. *New : Windows Server 2012 R2 support added. *Fixed : Product crash error during event collection. *Fixed : Alert for Configuration Permission Changes - 2008 Servers. *Fixed : Move Containers/Contacts reporting. *Fixed : GPO User/Computer Configuration count mismatch. *Fixed : Share based reports - Files created report fix. Version 4.6.0 (4640) Build
ManageEngine ADAudit Plus 4.6.0 Build Number: 4661 Released
Dear All, Greetings from ManageEngine ADAudit Plus! ADAudit Plus latest build 4661 announces custom reports in ADAudit Plus, now create reports you desire in a few clicks. Chose from the pre-configured report categories and chose the sub-categories. Further, chose the columns and add filters if you further want to drill down information for precise data. Last but not the least, you could schedule the same to be periodically e-mailed. With ADAudit Plus, enhance your Windows Server environment auditing:
File or Folder Accessed by shows nothing
Hi On my reports for File or Folder Changes does not show accessed by - is there a specific setting I need to change to show who the file or folder was accessed by?? Thanks RTTAdmin
Logging a specific event ID - skeleton key malware
I would like to log event IDs 7045 and 7036 for the psexecsvc service as detailed here http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/ Can ADAP do this without auditing processes - which causes a large amount of data on the domain controllers? i.e. just look for an event Id and check for the process start? Or do I need some other software to do this? Thanks Ian
krbtgt/domain
I get what this account does based on reading from here http://technet.microsoft.com/en-us/library/dn745899.aspx#Sec_KRBTGT but cannot find out what is using it though. This shows up in the log daily that the account has failed to login on many systems. Can someone break it down for me in dummy terms? Thanks
Need help setting up AD Alert
Hello everyone. I just downloaded the application and using the trial in hopes it would fit what I am trying to accomplish. In short, I want to get an email alert when a particular user authenticates to the domain. Whether the logon type is RDP, via UNC path, SMB, basically log the authentication request for this one user on the domain. the report should include all requests but only one email should go out upon initial authentication. We can then review the report to see what was done and authenticated.
ADAudit - Password expiration alert
hello I can generate alerts as one organizational unit when their password is expiring in a given time? regards
Lot's of login attempts from a single user
Hey all, We just installed AD Audit into our environment and I am loving it. What I'm curious about is why do some users for a single day have 12000+ successful login attempts? Then the next day they have 20? Is it normal for a Domain User to authenticate that many times to our domain controllers? I just find it shocking. What could cause this sort of authentication activity? Any direction or help is much appreciated! Thank you.
Audit/Monitor for Folder/file only
The file audit connects via shares and I have a folder in that share that I need to create a report & alert for whenever it's accessed. I can't seem to figure out how to monitor, alert or create a report for a single file or folder. Ideas?
Temp folder contains thousands of ReportResults
Hello, the ADAudit Plus\temp folder contains over 200,000 files and about 1,500 files are generated each day. Why are these files are written? How will the files be deleted? Best regards
Check for ActiveSync enable
Is there some way to configure a report to show me when ActiveSync is enabled on an AD account?
Add ram to java process
Hi. I have several ManageEngine products and in some of them, when de server is cappable, I've added more ram to the java process modifying the wrapper.conf file. Can some one provide me the correct procedure to do some in AdAditPlus? Scince I find more thas one wrapper.con file with several warnings I don't to mess the server. Reggards Juan
Audit Policy Configuration getting error
Hello I have installed ADAudit and the service account running everything is a domain admin. When i press the "Click here" for configuring the Default Domain Controller Policy, i get the error: PolicyStatusUnspecified error - Error Code:80004005 Why is that ?
File and Folder Audit Summary Reports
Is there a way to get file and folder audit summary reports that are Per Server and also Per Share. We would like to get a summary of the file and folder activities (create, delete, move, copy, rename, etc.) at the server level and also at the share level. The summary view at the domain level is good but we want to narrow it down a bit so that our data owners and server owners know the activity occurring at the levels they are familiar with. Thank you.
Monitoring size of copied files
Anyone know if there is a way within ADAudit Plus to monitor the size of data copied to a share over time?
Can you see changes to file in a certain path?
We have a file server with auditing enabled. At some point someone deleted and or moved a folder. We would like to know who did it. I can't seem to find a way to "filter by path". Is this possible?
"Make as Default" option on a report does not save the selections
The "Make as Default" option should also save the selections. For example, the "Logon Activity based on DC" report has a selection box to choose the domain controllers. Each time I open this report, it always defaults to only the first DC in alphabetical order, so I have to change it to add all of my DC's. It would be more efficient if it saved my server selection as default (on this and other reports with selections). PS- I like the "Frequently Locked Out Users" cumulative report. Now I can see
Automated Reporting Customization
Hey there, So far, I have enjoyed using ADAudit Plus, however the canned reports are rather limiting. For example, the Recently Modified Users report is displaying a lot of msExchMailboxAuditLastAdminAccess logs. Although this information is helpful to log, I would not want this included in my report nor any false positives, I would prefer to only have any anomalies sent to my e-mail. How are your clients leveraging the reporting? In my case, what options are available for me to customize these reports
Graph for reporting - AD Audit Plus
We have purchased the licensed version of AD Audit Plus and I am trying to report on 'frequently locked out' users, 'recently unlocked users'. I particularly like the graphs on the homepage, however cannot export / run graphs for management. Where can export the graphic views to a spreadsheet for analysis? Thank you,
Monitor in ADAudit?
Hi, Is the something we can monitor in ADAudit? *Domain admin account creation * Account and group deletion * ACL modifications in AD (groups) * ACL modifications in filesystem * ACL modifications in mailboxes * Where domain admins log on (servers) Thanks Erik
Alert for self reset ad password
Hi, I would like to have an alert each time a user with rights on AD uses it to self reset his password (to bypass the domain password policy) Is that possible ?
Exclude group from AD Auditing
Hi, I'm currently testing ADAudit Plus for my company. I saw in the configuration we could exclude AD users of the audit, particularly for service accounts . Is it possible to do the same for AD groups? I have a number of Exchange distribution list that are updated automatically by script according to information from our HR software , and suddenly it completely false reports (all employees are first removed from the group and then reimported ) I would like these groups to not be considered since
Next Page