Report logged in users in real-time?

Rogue

Banned
Jan 28, 2000
5,774
0
0
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?
 

Fardringle

Diamond Member
Oct 23, 2000
9,200
765
126
There may be more graceful methods, but you can set up auditing for his account that sends you an alert notification on any successful login attempt. I'm not sure if you can do the same for when he logs out of the system, but it could be a place to start until someone else pops in with a better solution. :)
 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
Originally posted by: Rogue
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?


Just get it in writing. The chance of missing a critical OS or Exchange patch goes up every week, and eventually it'll go down hard, and you can point at him and say "I told you so"
 

Rogue

Banned
Jan 28, 2000
5,774
0
0
Originally posted by: nweaver
Originally posted by: Rogue
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?


Just get it in writing. The chance of missing a critical OS or Exchange patch goes up every week, and eventually it'll go down hard, and you can point at him and say "I told you so"

I'm dealing with a combat engineer trained, US Army Colonel here. I've likened NOT patching the system to allowing troops on the perimeter to fall asleep and allow the enemy to infiltrate the CP (command post) and he doesn't care. I've fought this battle to the farthest extent possible, short of shooting the man. Besides, I'd like to know how often he's actually on the system, because he would have us believe that he's on it nearly 24/7.
 

Brazen

Diamond Member
Jul 14, 2000
4,259
0
0
Originally posted by: Rogue
Originally posted by: nweaver
Originally posted by: Rogue
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?


Just get it in writing. The chance of missing a critical OS or Exchange patch goes up every week, and eventually it'll go down hard, and you can point at him and say "I told you so"

I'm dealing with a combat engineer trained, US Army Colonel here. I've likened NOT patching the system to allowing troops on the perimeter to fall asleep and allow the enemy to infiltrate the CP (command post) and he doesn't care. I've fought this battle to the farthest extent possible, short of shooting the man. Besides, I'd like to know how often he's actually on the system, because he would have us believe that he's on it nearly 24/7.

Follow him home and wait till he goes to sleep, then reboot the server.
 

spherrod

Diamond Member
Mar 21, 2003
3,897
0
0
www.steveherrod.com
Originally posted by: Rogue
Originally posted by: nweaver
Originally posted by: Rogue
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?

That's ridiculous - can you not go to his superiors at all?


Just get it in writing. The chance of missing a critical OS or Exchange patch goes up every week, and eventually it'll go down hard, and you can point at him and say "I told you so"

I'm dealing with a combat engineer trained, US Army Colonel here. I've likened NOT patching the system to allowing troops on the perimeter to fall asleep and allow the enemy to infiltrate the CP (command post) and he doesn't care. I've fought this battle to the farthest extent possible, short of shooting the man. Besides, I'd like to know how often he's actually on the system, because he would have us believe that he's on it nearly 24/7.

 

Brazen

Diamond Member
Jul 14, 2000
4,259
0
0
Originally posted by: spherrod
Originally posted by: Rogue
Originally posted by: nweaver
Originally posted by: Rogue
Is there anyway to report in real-time when a users logs on and off in an Active Directory environment? I'm not talking about checking event logs, I'm talking about something like an SNMP message or something that can be triggered and sent in real-time. Does anyone have an idea or experience doing such a thing?

Here's the reason. We have a high ranking member of the staff that insists that our Exchange servers NEVER under any circumstances be taken down, rebooted, etc. I would like to know when he is actually logged in to the network and/or in his mailbox even. I have a system called IT Monitor that can capture SNMP data and report it any way I wish. Any ideas?

moved

Just get it in writing. The chance of missing a critical OS or Exchange patch goes up every week, and eventually it'll go down hard, and you can point at him and say "I told you so"

I'm dealing with a combat engineer trained, US Army Colonel here. I've likened NOT patching the system to allowing troops on the perimeter to fall asleep and allow the enemy to infiltrate the CP (command post) and he doesn't care. I've fought this battle to the farthest extent possible, short of shooting the man. Besides, I'd like to know how often he's actually on the system, because he would have us believe that he's on it nearly 24/7.
That's ridiculous - can you not go to his superiors at all?
fixed (did the same thing to me when I replied)
 

dphantom

Diamond Member
Jan 14, 2005
4,763
327
126
You mentioned Exchange servers. Are they in a clustered environment?
 

spydernet

Junior Member
Sep 26, 2005
6
0
0
Ask him whether his car can work non-stop...ie, without petrol...then of course he will say no...if he is normal ;) then tell him every machine need some fuel to .....ask him go to SLEEP !!! :p
 

blemoine

Senior member
Jul 20, 2005
312
0
0
How bout this idea. Schedule a reboot for middle of the night or early morning. Are you in danger of getting fired for going against that A-hole and rebooting. if so maybe a change of scenery is in order. good luck
 

Rilex

Senior member
Sep 18, 2005
447
0
0
Exchange records the last log on and log off time in the ESM.

You could also go to technet.microsoft.com and look at some asynch. queries they have in the scripting section that use event sinks.