Confirm that your Alerts have been configured for the correct Event Definitions. In the Audit Reports, create a new report using the same Event Definitions as the filter as well as the corresponding Event IDs that would be logged on the DC.
If the Audit Reports are empty, this implies the events were not captured. Please confirm that the GPO used to set the Audit Policy on the DCs (typically the Default domain Controllers Policy) has the minimum required for AA configured for the Audit Policy settings:
- Audit Logon Events - Success, Failure
- Audit Account Logon - Success
- Audit Account Management - Success
- Audit Directory Service Access - Success
- Audit Policy Change - Success
- Audit System Events - Success
If the GPO has the minimum needed, confirm the settings are getting applied properly on the DCs by logging into a DC and running Secpol.msc:
1. Run secpol.msc
2. Expand Local Policy | Audit Policy
3. Confirm the settings are the same as what is configured in the GPO. If not, there is an issue with the setting getting applied to the DC.
Confirm that the events for the changes you want to audit are getting logged on the DCs. Using Active Directory Users and Computers, bind to a specific DC. Make a change that you want to audit (user change, group change, etc) and check the Security Event log on the DC that you bound to see if the event ID for that change was logged. If the events are not logged on the DC, AA will never be able to report on the changes.
If the events are logged on the DC, and the Audit Reports show the changes, please see the following KB article for more alert troubleshooting steps:
https://support.quest.com/active-administrator/kb/sl3784/email-alerts-in-active-administrator-are-not-received