Direct Inward Dialing: +1 408 916 9892
Windows Event Viewer is the default native Active Directory(AD) tool that administrators use to track changes made to their system. This is a good tool to use to check if security policies were meddled with or if any default system settings were changed. You can also view if any malfunctioning applications have reported status or error messages. This is a pretty workable solution except for one small snag- you don't know whether an application on your system actually uses the Event Viewer to record its events. This would mean that you'll spend hours perusing your event logs looking for a specific application's logs, without ever really knowing if the application records its logs or not.
EventLogSourceView is a freeware tool to solve this problem. The tool is a simple, tabular display of all the events being recorded to your logs along with the 'Event Source Names'. A quick glance at the 'Event Source Names' columns would save you the hours you'd have spent working through 'the noise' you'd normally find on the more vanilla 'Windows Event Viewer'. EventLogSourcesView also provides you with other necessary information such as version related details obtained from the DLL/EXE file- File Description, File Version, Product Name, Company. Additionally every event log source also lists DLL/EXE files that contain event messages, Registry Modified Times, and Event Types.
Once you've set up the tool, you can easily look through the logs in the viewer to identify if a particular application is logging its messages. You can select the 'Registry Modified' column to sort the list in order of recently installed applications. If you find no logs related to the malfunctioning application, you'll know that the application isn't logging events by itself. In any case you'll still have numerous application related logs that might prove useful.
While EventLogSourceViewer is an upgraded flavor to the standard Event Viewer, if you're looking for a more advanced solution for AD auditing and reporting, you can try out ADAudit Plus.
ADAudit Plus is a comprehensive AD solution that simplifies AD auditing and reporting. Its intuitive user interface, pre-configured reports, and advanced filter options make it easy for you to track changes to your network, and detect threats immediately. You get a fully equipped dashboard that gives you a holistic view of the various systems in your network. This way you can correlate events across the network and spot suspicious behavior.
ADAudit Plus is a real-time, web-based Windows Active Directory (AD) change reporting software that audits, reports and alerts on Active Directory, Windows servers and workstations, and NAS storage devices to meet the demands of security, and compliance requirements. You can track AD management changes, processes, folder modifications, permissions changes, and more with 200+ reports and real-time alerts. To learn more, visit ADAudit Plus.
Try ADAudit Plus to audit, track, and respond to malicious activities happening inside your Windows AD & Azure environment.
Try ADAudit Plus for free