立即与支持人员聊天
与支持团队交流

Active Administrator 8.6.3 - User Guide

Active Administrator Overview User Provisioning Certificates Security & Delegation  Active Directory Health
Switching to Active Directory Health Using the Active Directory Health landing page Installing Active Directory Health Analyzer agents Using the Active Directory Health Analyzer agent configuration utility Excluding domain controllers Managing the Remediation Library Analyzing Active Directory health Analyzing Azure Active Directory Managing Active Directory Health Analyzer alerts Managing alert notifications Pushing alerts to System Center Operations Manager and SNMP managers Managing monitored domain controllers Managing data collectors Active Directory Health Templates Managing Active Directory Health Analyzer agents Using the Troubleshooter Recovering Active Directory Health data
Auditing & Alerting Group Policy Active Directory Recovery Active Directory Infrastructure DC Management DNS Management Configuration
Using the Configuration landing page Managing tasks Defining role-based access Setting email server options Configuring SCOM and SNMP Settings Setting notification options Setting Active Template options Setting agent installation options Setting recovery options Setting GPO history options Setting certificate configuration Setting service monitoring policy Managing archive databases Migrating data to another database Setting a preferred domain controller Setting up workstation logon auditing Managing configuration settings Setting user options Managing the Active Directory server
Diagnostic Console Alerts Appendix
Domain controller alerts
Active Directory Certificate Services service is not running Active Directory Domain Services is not running Active Directory Web Services service is not running Consecutive replication failures DC cache hits DC DIT disk space DC DIT log file disk space DC LDAP load DC LDAP response too slow DC Memory Usage DC properties dropped DC RID pool low DC SMB connections DC SYSVOL disk space DC time sync lost Detected NO_CLIENT_SITE record DFS Replication service not running DFS service is not running DFSR conflict area disk space DFSR conflict files generated DFSR RDC not enabled DFSR sharing violation DFSR staged file age DFSR staging area disk space DFSR USN records accepted DFSRS CPU load DFSRS unresponsive DFSRS virtual memory DFSRS working set DNS Client Service is not running Domain controller CPU load Domain controller page faults Domain controller unresponsive File Replication Service is not running File replication (NTFRS) staging space free in kilobytes GC response too slow Group policy object inconsistent Hard disk drive Intersite Messaging Service is not running Invalid primary DNS domain controller address Invalid secondary DNS domain controller address KDC service is not running LSASS CPU load LSASS virtual memory LSASS working set Missing SRV DNS record for either the primary or secondary DNS server NETLOGON not shared NetLogon service is not running Orphaned group policy objects exist Physical memory Power supply Primary DNS resolver is not responding Secondary DNS resolver is not responding Security Accounts Manager Service is not running SRV record is not registered in DNS SYSVOL not shared W32Time service is not running Workstation Service is not running
Domain alerts Site alerts Forest alerts Azure Active Directory Connect alerts
Event Definitions PowerShell cmdlets About us

Event Definitions

Previous Next



Event definitions are used to create alerts and reports. The event definitions file, EventDefinitions.edx, is located in the Active Administrator\Server folder. Occasionally new event definition files are made available. You can import these new event definitions into your auditing database. See Managing event definitions.

Table 148. Event Definitions

Event

Type

Active Administrator AFS Service Started

Active Administrator

Active Administrator AFS Service Stopped

Active Administrator

Active Administrator Alert Added

Active Administrator

Active Administrator Alert Deleted

Active Administrator

Active Administrator Alert Updated

Active Administrator

Active Administrator Audit Agent Activated

Active Administrator

Active Administrator Audit Agent Configuration Changed

Active Administrator

Active Administrator Audit Agent Installation Failed

Active Administrator

Active Administrator Audit Agent Installation Succeeded

Active Administrator

Active Administrator Audit Agent Moved

Active Administrator

Active Administrator Audit Agent Uninstalled

Active Administrator

Active Administrator Delegation Added

Active Administrator

Active Administrator Delegation Broken

Active Administrator

Active Administrator Delegation Removed

Active Administrator

Active Administrator Delegation Repaired

Active Administrator

Active Administrator Delegation Updated

Active Administrator

Active Administrator DNS Test Failed

Active Administrator

Active Administrator DNS Test Succeeded

Active Administrator

Active Administrator Domain Controller Excluded

Active Administrator

Active Administrator Event Definition Disabled

Active Administrator

Active Administrator Event Definition Enabled

Active Administrator

Active Administrator Event Purge History Cleared

Active Administrator

Active Administrator Event Purged / Archived

Active Administrator

Active Administrator Global Alert Quiet Time Added

Active Administrator

Active Administrator Global Alert Quiet Time Changed

Active Administrator

Active Administrator Global Alert Quiet Time Removed

Active Administrator

Active Administrator GPO History Backups Purged

Active Administrator

Active Administrator GPO Rollback Completed

Active Administrator

Active Administrator GPO Rollback Failed

Active Administrator

Active Administrator GPO Rollback Started

Active Administrator

Active Administrator Group Policy Object Added to the Repository

Active Administrator

Active Administrator Group Policy Object Checked Into the Repository

Active Administrator

Active Administrator Group Policy Object Checked Out of the Repository

Active Administrator

Active Administrator Group Policy Object Published to Active Directory

Active Administrator

Active Administrator Group Policy Object Removed from the Repository

Active Administrator

Active Administrator Group Policy Object Restored

Active Administrator

Active Administrator new Domain Controller Discovered

Active Administrator

Active Administrator Trustee Added

Active Administrator

Active Administrator Trustee Removed

Active Administrator

Active Directory Backup Completed

Active Administrator

Active Directory Backup Failed

Active Administrator

Active Directory Backup Purge History Cleared

Active Administrator

Active Directory Backup Started

Active Administrator

Active Directory Backups Purged

Active Administrator

Active Directory Replication Test Failed

Active Administrator

Active Directory Replication Test Succeeded

Active Administrator

Active Directory Restore Completed

Active Administrator

Active Directory Restore Failed

Active Administrator

Active Directory Restore Started

Active Administrator

Active Directory Shared Folder Changed

Shared Folder

Active Directory Shared Folder Created

Shared Folder

Active Directory Shared Folder Deleted

Shared Folder

AD Object Changed

General

AD Object Created

General

AD Object Renamed / Moved

General

Audit Agent Database Connectivity Lost

Active Administrator

Audit Agent Database Connectivity Restored

Active Administrator

Azure AD Group Added

Azure AD

Azure AD Group Deleted

Azure AD

Azure AD Group Updated

Azure AD

Azure AD User Added

Azure AD

Azure AD User Deleted

Azure AD

Azure AD User Updated

Azure AD

Certificate Added to Repository

Active Administrator

Computer Account Changed

Computer

Computer Account Created

Computer

Computer Account Deleted

Computer

Contact Changed

Contact

Contact Created

Contact

Contact Deleted

Contact

Domain Master Changed

FSMO

Domain Trust Created (Windows 2000 only)

Trust

Event Log Cleared

Security

Global Distribution Group Changed

Group

Global Distribution Group Created

Group

Global Distribution Group Deleted

Group

Global Group Changed

Group

Global Group Created

Group

Global Group Deleted

Group

GPO Changed

Group Policy

GPO Created

Group Policy

GPO Deleted

Group Policy

GPO Password Complexity Disabled

Group Policy

GPO Password Complexity Enabled

Group Policy

GPO Security Group Filters Changed

Group Policy

Group Policy Links Changed

Group Policy

Group Type Changed

Group

Infrastructure Master Changed

FSMO

Kerberos authentication ticket (TGT) was requested

User

Kerberos Pre-Auth Failed (Bad Password)

User

Local Distribution Group Changed

Group

Local Distribution Group Created

Group

Local Distribution Group Deleted

Group

Local Group Changed

Group

Local Group Created

Group

Local Group Deleted

Group

Logged onto DC (Local)

User

Logged onto DC (Remote)

User

Logon Failed (Bad Password)

User

Logon Failed (NTLM - Bad Password)

User

Logon Failed (NTLM - Unknown Username)

User

Logon Failed (Unknown Username)

User

Member Added to BUILTIN Group

Group Membership

Member Added to Global Distribution Group

Group Membership

Member Added to Global Group

Group Membership

Member Added to Local Distribution Group

Group Membership

Member Added to Local Group

Group Membership

Member Added to Universal Distribution Group

Group Membership

Member Added to Universal Group

Group Membership

Member Removed from BUILTIN Group

Group Membership

Member Removed from Global Distribution Group

Group Membership

Member Removed from Global Group

Group Membership

Member Removed from Local Distribution Group

Group Membership

Member Removed from Local Group

Group Membership

Member Removed from Universal Distribution Group

Group Membership

Member Removed from Universal Group

Group Membership

Object Owner Changed

Security

Object Permissions Changed

Security

One Way Incoming Trust Created

Trust

One Way Outgoing Trust Created

Trust

OU Changed

Organizational Unit

OU Created

Organizational Unit

OU Deleted

Organizational Unit

PDC Master Changed

FSMO

Printer Changed

Printer

Printer Created

Printer

Printer Deleted

Printer

Rejected Simple LDAP Bind Requests

LDAP Signing

Repository Certificate Delete

Active Administrator

Repository Certificate Updated

Active Administrator

RID Master Changed

FSMO

Schema Master Changed

FSMO

Site Changed

Site

Site Created

Site

Site Deleted

Site

SMTP Virtual Directory Changed

Exchange Server

Subnet Changed

Subnet

Subnet Created

Subnet

Subnet Deleted

Subnet

System Audit Policy Was Changed

Group Policy

System Time was Changed

System

Trust Deleted

Trust

Trust Modified

Trust

Two Way Trust Created

Trust

Universal Distribution Group Changed

Group

Universal Distribution Group Created

Group

Universal Distribution Group Deleted

Group

Universal Group Changed

Group

Universal Group Created

Group

Universal Group Deleted

Group

Unsigned LDAP Client Details

LDAP Signing

User Account Changed

User

User Account Created

User

User Account Deleted

User

User Account Disabled

User

User Account Enabled

User

User Account Locked Out

User

User Account Type Changed

User

User Account Unlocked

User

User Attribute Changed

User

User Change Password Attempt Failed

User

User Change Password Attempt Succeeded

User

User Locked Workstation

Workstation

User Logoff

Workstation

User Logon (Interactive for Windows 2012 Server)

Workstation

User Logon (Interactive for Windows 2016 Server)

Workstation

User Logon (Interactive)

Workstation

User Logon (Remote Desktop)

Workstation

User Password Reset

User

User Unlocked Workstation

Workstation

Windows Shutdown

System

Windows Started

System

 

PowerShell cmdlets

Previous Next



Microsoft® Windows PowerShell® is a Windows® command-line shell and scripting language designed specifically for system administrators and built on top of the Microsoft .NET Framework. Active Administrator supports the use of PowerShell cmdlets.

Topics 

What are cmdlets?

Previous Next


PowerShell cmdlets > What are cmdlets?

What are cmdlets?

Windows PowerShell® has the concept of cmdlets. A cmdlet is a simple, single-function command that manipulates objects and is designed to be used in combination with other cmdlets.

If you already had Windows PowerShell installed on your computer before you installed Active Administrator®, the Active Administrator cmdlets were automatically installed and registered with Windows PowerShell.

The examples in this section show you leverage the cmdlets available in Active Administrator. These cmdlets allow you to perform many of the functions of Active Administrator in an automation environment. The cmdlets also can be of great use in any environment where a repetitive process involving Active Administrator is needed.

The complete set of cmdlets shipped with the module AA.ServerManagerPowerShellModule.dll is as follows.

Table 149. AA Server Manager cmdlets for use with Windows PowerShell®

Cmdlet

Module

Reference

Clear-AFSCache

AA.ServerManagerPowerShellModule

Clearing the AFS cache

Get-AAFeaturesLicenseStatus*

AA.ServerManagerPowerShellModule

Getting the status of Active Administrator licenses

Get-AAWebServerConfiguration

AA.ServerManagerPowerShellModule

Getting configuration settings for the Web server

Get-ADSLoggingStatus

AA.ServerManagerPowerShellModule

Getting logging status for ADS

Get-ADSOperationStatus*

AA.ServerManagerPowerShellModule

Getting operation status for ADS

Get-ADSPort

AA.ServerManagerPowerShellModule

Getting the port number for ADS

Get-AFSLoggingStatus

AA.ServerManagerPowerShellModule

Getting logging status for AFS

Get-AFSOperationStatus*

AA.ServerManagerPowerShellModule

Getting operation status for AFS

Get-AFSPort

AA.ServerManagerPowerShellModule

Getting the port number for AFS

Get-AFSHTTPOperationStatus

AA.ServerManagerPowerShellModule

Getting operation status for the HTTP service

Get-FullTextSearchStatus

AA.ServerManagerPowerShellModule

Getting the status of Full-Text Search

Get-NotificationService
OperationStatus*

AA.ServerManagerPowerShellModule

Getting operation status for the Active Administrator Notification Service

Set-AALicense

AA.ServerManagerPowerShellModule

Updating the Active Administrator license

Set-AAWebServerConfiguration

AA.ServerManagerPowerShellModule

Setting configuration for the Active Administrator Web server

Set-ADSPort

AA.ServerManagerPowerShellModule

Setting the port for ADS

Set-AFSAndADSStartup
Account

AA.ServerManagerPowerShellModule

Setting the startup account for AFS and ADS

Set-AFSPort

AA.ServerManagerPowerShellModule

Setting the port for AFS

Set-NotificationServiceStartup
Account

AA.ServerManagerPowerShellModule

Setting the startup account for the Active Administrator Notification Service

Switch-ADSLoggingStatus

AA.ServerManagerPowerShellModule

Switching logging status of ADS

Switch-ADSOperationStatus

AA.ServerManagerPowerShellModule

Switching operation status of ADS

Switch-AFSLoggingStatus

AA.ServerManagerPowerShellModule

Switching logging status of AFS

Switch-AFSOperationStatus

AA.ServerManagerPowerShellModule

Switching operation status of AFS

Switch-AFSHTTPOperationSatus

AA.ServerManagerPowerShellModule

Switching operation status of the HTTP service

Switch-FullTextSearchStatus

AA.ServerManagerPowerShellModule

Switching the setting of Full-Text Search

Switch-NotificationService
OperationStatus

AA.ServerManagerPowerShellModule

Switching operation status of the Active Administrator Notification Service

Using Active Administrator cmdlets

Previous Next


PowerShell cmdlets > Using Active Administrator cmdlets

Using Active Administrator cmdlets

The Active Administrator® cmdlets function very similarly to the included utilities in the AA Server Manager application. The cmdlets are located at C:\Program Files\Quest\Active Administrator\Server\PowerShell.

Viewing help

You can view help by typing the cmdlt name with no arguments or by using get-help.

Running cmdlets

You can run the cmdlets from the PowerShell console (right-click the cmdlet, and choose Run with PowerShell) or PowerShell ISE (open the cmdlet in ISE and click Run).

Using cmdlets manually

If you want to use the cmdlets manually, you must include the two cross-cutting scripts for configuration (ConfigAndLoadModule.ps1) and rights management (EnsureElevatedPrivileges.ps1).

Example

if(-Not(&($PSScriptRoot + "\ConfigAndLoadModule.ps1"))){ exit; }

Example

if(-Not(&($PSScriptRoot + "\EnsureElevatedPrivileges.ps1") -scriptPath $myinvocation.mycommand.definition)){ exit; }

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级