SIEM, Log Management, Security, Compliance, Server Monitoring and Uptime Monitoring Software

Real-Time Success Logon Monitoring and Reporting with Server Manager

March 25th, 2022

In this article I am going to show you:

  • How to receive real-time notifications when administrator accounts log into a domain member server.
  • How to filter out specific administrator accounts.
  • How to generate daily successful logon reports.

Table of Contents

How to Add Domain Controllers and Stand-Alone Servers

The first step in this process is to add your domain controllers and stand-alone servers to the software.

How to Configure the Success Logon Template

Once you have added your domain controllers to the software, we need to create a Success Logon Monitor Template then assign it to the target domain controllers or stand-alone servers. If your not familiar with Corner Bowl Software, Templates define instructions such as which Event Logs to monitor and the frequency to monitor the event log entries. Once created, you assign the Template to the hosts which you would like to monitor.

How to Assign Servers to the Template

Ok the last step is assigning your Domain Controllers or stand-alone servers to the template.

Putting it All Together

How to Configure and View the Success Logon Report

Once we have configured Event Log Consolidation and the template has either been manually or automatically executed, we need to create a Success Logon Monitor Report then assign the target domain controllers or stand-alone servers to the report. If your not familiar with Corner Bowl Software, Reports define instructions such as which Event Logs to report on, filters to apply and the frequency to run the report. Once created, you assign Hosts to the report.

  • Server Manager comes pre-configured with a Security Event Log Successful Logons Report. The report can be found in the Explorer View. Find the root Reports node then expand Sample Reports | Event Logs | Security Reports | Logon.
  • Here you will find 3 different reports.
    ReportDescription
    Security Event Log Failed Logons ReportReports on failed logon attempts.
    Security Event Log Logon Sessions ReportReports on logon sessions.
    Security Event Log Successful Logons ReportReports on successful logons.

  • Right click on the Security Event Log Successful Logons Report, then select Properties. The Security Event Log Successful Logons Report Properties View displays.
  • Use the General Tab to schedule the report.
  • Use the Explicitly Assigned Logs Tab to assign archived and auxiliary consolidated logs as well as native EVTX log file backups.
    Note
    Leave these lists blank when you only want to include entries from the Primary Log Repository.
  • Use the Options Tab to select the Event Log IDs and Logon Types to include. You also have the option of including a Summary Table as well as collapsing the results to show a unique list of logons and logon types.
    Success Logon Monitor Options View
    Success Logon Monitor Options View
  • Use the Date/Time Range Tab to specify the date range to include in the report.
  • Use the Filters Tab to filter the accounts to monitor as well as provide any standard Event Log Entry Filters you would like to apply.
  • The Actions Tab enables you to assign the actions when the report state changes. Use the On Complete Drop-Down to assign actions to fire when the report is complete. Notice the Send an Email action is pre-assigned. Double-clicking on the action displays the Action Properties View.
  • Use the Recipients Drop-Down to select an email address then click Close and save your changes when prompted.
  • Finally, use the Hosts Drop-Down to assign the domain controllers or stand-alone servers you want to include in the report.
    Success Logon Report Properties Complete
    Success Logon Report Properties Complete
  • Once assigned, click Save to save your changes then click View Report to view the report directly in the Management Console.
    Success Logon Report
    Success Logon Report
  • That's real-time success logon monitoring and scheduled reporting with Corner Bowl Server Manager.

Last Updated: March, 3rd 2024