Adding AD Audit Plus
Note: Ensure Log360 Cloud agent is installed on at least one Windows device in your network. To configure the agent, follow the steps provided
here.
- Log into your Log360 Cloud dashboard.
- Navigate to Settings -> Configuration Settings -> Log source configuration -> Applications tab.
- From the right pane, click on the General Applications tab to view the list of applications being monitored.
- To add a new application, click on Add General Applications.
- Select AD Audit Plus from the Application Type drop down box.
- Expand the list by clicking the "+" icon to add a new device.
- Choose from the drop-down menu to add Configured devices, Workgroup devices, domain devices, etc.
- To add new devices manually, click on Configure Manually and enter Log Source.
- Click on Select and Add to add the log source.
- Use the Select Agent dropdown to select the device that is the agent to which the logs will be forwarded.
- The applications will now be added for monitoring.
Configuring ManageEngine ADAudit Plus
- Log in to ADAudit Plus and navigate to the Admin tab.
- Under Configuration, click SIEM Integration.
- Check Enable forwarding of ADAudit Plus Data check box.
- From the displayed component check Syslog/SIEM tab checkbox.
- Configure the following:
- Syslog/SIEM Server: IP address or host name of the Log360 Cloud Agent server
- Port: Any port that the Log360 Cloud agent server is listening to.
- Protocol: Select the protocol used by Log360 Cloud Agent server from the Protocol radio buttons.
- Syslog Standard: Select the desired syslog standard to forward logs from the Syslog Standard radio buttons.
- Select default options for Data format and Folder size threshold