Change Auditor for Authentication Services 7.0.2 - Event Reference Guide

Introduction

Authentication Services is patented technology that enables organizations to extend the security and compliance of Active Directory to UNIX, Linux, and Mac platforms and enterprise applications. Using Change Auditor, you can track, audit, report and alert on all critical changes to:

NOTE: Authentication Services auditing is only available when you have Authentication Services 4.0 (or later) installed and the Change Auditor for Authentication Services license applied. Contact your Sales Representative for more information on obtaining a Change Auditor for Authentication Services license.

This guide lists the events that can be captured by Change Auditor for Authentication Services. Separate event reference guides are provided that list the core Change Auditor events (when any Change Auditor license is applied) and the events captured when the different auditing modules are licensed.

Change Auditor for Authentication Services Events

Change Auditor for Authentication Services queries Active Directory for modifications made to the Authentication Services configuration container. This section lists the audited events captured by Change Auditor for Authentication Services. They are listed in alphabetical order by facility.

Table 1. Authentication Services Monitoring events

Authentication Services Computer Object Added

Created when a new Authentication Services computer object is added to an Active Directory domain.

Medium

Authentication Services Computer Object Attribute Changed

Created when an attribute for an Authentication Services computer object is changed.

Medium

Authentication Services Computer Object Deleted

Created when an Authentication Services computer object is removed from an Active Directory domain.

Medium

Authentication Services Computer Object Moved

Created when an Authentication Services computer object is moved in an Active Directory domain.

Medium

Authentication Services Computer Object Renamed

Created when an Authentication Services computer object is renamed in an Active Directory domain.

Medium

Authentication Services GPO Setting Changed

Created when an Authentication Services group policy settings is changed.

Medium

NIS Object Added

Created when an NIS object is added to Active Directory.

Medium

NIS Object Attribute Changed

Created when the data stored in an NIS object in Active Directory is changed.

Medium

NIS Object Deleted

Created when an NIS object is deleted from Active Directory.

Medium

NIS Object Moved

Created when an NIS object is moved within Active Directory.

Medium

NIS Object Renamed

Created when an NIS object is renamed within Active Directory.

Medium

Personality Object Added

Created when a UNIX user or group personality object is added to Active Directory.

Medium

Personality Object Attribute Changed

Created when the data stored in a Unix personality object in Active Directory is changed.

Medium

Personality Object Deleted

Created when a Unix user or group personality object is deleted from Active Directory.

Medium

Personality Object Moved

Created when a Unix personality object is moved within Active Directory.

Medium

Personality Object Renamed

Created when a Unix personality object is renamed within Active Directory.

Medium

UNIX GECOS Changed

Created when the GECOS attribute of a Unix-enabled Active Directory user is changed.

Medium

UNIX Group ID Number Changed for Group

Created when the group ID number of a Unix-enabled Active Directory group is changed.

Medium

UNIX Group ID Number Changed for User

Created when the primary group ID number of a Unix-enabled Active Directory user is changed.

Medium

UNIX Group Name Changed

Created when the Unix name of a Unix-enabled Active Directory group is changed.

Medium

UNIX Home Directory Changed

Created when the Unix home directory of a Unix-enabled Active Directory user is changed.

Medium

UNIX Login Name Changed

Created when the Unix login name of a Unix-enabled Active Directory user is changed.

Medium

UNIX Login Shell Changed

Created when the Unix login shell of a Unix-enabled Active Directory user is changed.

Medium

UNIX User ID Number Changed

Created when the user ID number of a Unix-enabled Active Directory user is changed.

Medium

UNIX-Enabled Changed for Group

Created when the Unix attributes of an Active Directory group are changed such that it no longer exists on a Unix or Linux® system.

Medium

UNIX-Enabled Changed for User

Created when the Unix attributes of an Active Directory user are changed such that it no longer exists on a Unix or Linux system.

Medium

UNIX-Enabled Group Created

Created when a new Active Directory group with configured Unix attributes is created.

Medium

UNIX-Enabled Group Deleted

Created when a Unix-enabled Active Directory group is deleted.

Medium

UNIX-Enabled User Created

Created when a new Active Directory user with configured Unix attributes is created.

Medium

UNIX-Enabled User Deleted

Created when a Unix-enabled Active Directory user is deleted.

Medium

Built-in Reports

Change Auditor provides predefined reports which allow you to quickly retrieve valuable change information from a variety of perspectives.

1
Click on the Searches tab or select the View | Searches menu command or Ctrl+F10 to open the Searches page.
2
Expand and select the appropriate folder in the explorer view (left-hand pane) to display the list of search definitions stored in the selected folder. For example, selecting the Shared | Built-in | Authentication Services will display all the built-in searches available for Authentication Services.
Select the search definition and click the Run tool bar button at the top of the Searches page

The following built-in reports are available:

 

自助服务工具
知识库
通知和警报
产品支持
下载软件
技术说明文件
用户论坛
视频教程
联系我们
获得许可 帮助
技术支持
查看全部
相关文档