11-25-2013 06:55 AM
folks
i 'm hoping you can help me out with a cda query
i've set up 2 cda appliances and am in the process of pointing them at 2 ad servers but i think i've hit a problem
the setup guide for the cda requires a registry change to the ad server but we have 50+ ad servers and i'm getting resistance about making this change
in order to get all the event log info does the cda need to see every server handling logons?
if so can i ask for the logs to be written to a central server and have the cda read those logs?
this is not urgent so i'd be grateful any opinions
thanks to anyone taking the time to reply
Solved! Go to Solution.
11-26-2013 07:37 AM
Unfortunately Microsoft did not build a method of log consolidation that would apply to the Security Event Logs. All other logs can be consolidated if you are using Active Directory Log Consolidation with the exception of the Security Events Log. If you have 50+ authentication sources then you must register each one with the CDA server in order to pick up changes to those security event logs.
If CDA only connects to the 2 AD servers mentioned above then only events from those servers will be recorded and avaialbe for discovery by the WSA.
Good luck!!!
11-25-2013 10:47 AM
What registry change are you making? You should only have to do it on the two AD servers CDA will connect to, not all 50+
11-26-2013 07:46 AM
collin
thanks for your reply
the registry change is as per the cda install document
11-26-2013 07:37 AM
Unfortunately Microsoft did not build a method of log consolidation that would apply to the Security Event Logs. All other logs can be consolidated if you are using Active Directory Log Consolidation with the exception of the Security Events Log. If you have 50+ authentication sources then you must register each one with the CDA server in order to pick up changes to those security event logs.
If CDA only connects to the 2 AD servers mentioned above then only events from those servers will be recorded and avaialbe for discovery by the WSA.
Good luck!!!
11-26-2013 07:50 AM
tommy
many thanks for your help and contribution, its greatly appreciated
i've since logged a call with tac who tell me it should work as long as we follow exactly what the cda guide says so we'll give it a try
our server folks are shy about making registry changes to their servers so we'll test this option first
i'll update the post when/if i make some progress
thanks again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide