Hi guys, fairly new to this, we are being requested to have some type of AD Monitoring/Event tracking and notification system for when someone makes a change on AD, etc. Would I need to be looking at a SIEM or another type of tool? Any suggestions?

3 Spice ups

I’ve not used it myself but Quest (Now owned by Dell) have the Change Auditor product for Active Directory:

http://software.dell.com/products/change-auditor-for-active-directory/

You can have a look on our Lepide auditor suite ( Active Directory Auditing Tool - Audit & Report AD Changes ) that exactly meets to your requirement and would be a perfect approach to resolve active directory auditing purpose. It helps to audit all the critical changes into real time and alerts immediately by sending customized email notification.

There is Netwrix Auditor for Active Directory solution (20 day of free trial) with real-time alerting and more than 200 predefined reports to show you any changes you need.

And in case you just need SIEM without reports you can always use free Netwrix Event Log Manager it collects and consolidates event logs from multiple computers across the network, provides archiving, and generates alerts.

@Netwrix

2 Spice ups

Hi Lucas – You may want to look into a tool that specializes in log management. Since you’re new to this area, something like TIBCO LogLogic might be able to help you out with AD monitoring / event tracking. When it comes to ease of use, the tool will make it easy to build and execute queries. With LogLogic, you’ll be able to ingest data from any source and gain insight with real-time alerting, correlation, and visual analytics. If you’d like to learn more about how LogLogic might be able to help you, you can go here or reach out to me for more info. Hope this helps - let me know if I can be of further assistance!

Hi Lucas,

You can look at ADAudit Plus for all your Active Directory Audit requirements:

For extensive event tracking and notifications, look at our SIEM solutions - Event Log Analyzer.

Both the solutions come with a 30-days fully functional free trial besides a free edition.

Will be happy to assist on any queries you might have.

@ManageEngine