Re: [fw-wiz] Getting windows user name?

Some vendors will install agents on various AD servers to cull the
information from the security logs and correlate them with last-logged-on
user information from the those same logs. Unfortunately, there doesn't
appear to be a single log entry in AD that has both user and IP address,
hence the need for correlation.
As a comparison, you can LDAP query Novell eDirectory for an IP and it will
return the username logged, but alas, not in AD.


-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx [mailto:firewall-
wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of ArkanoiD
Sent: Thursday, September 09, 2010 7:20 AM
To: Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] Getting windows user name?

Any chance to do that either

-- without netbios queries, via ldap
-- without requesting info from workstation itself, from AD directly?

firewall-wizards mailing list

firewall-wizards mailing list

Relevant Pages

  • RE: FW/IPS log correlation software
    ... As part of our Managed Security Services, we manage multiple enVision platforms and have successfully written alerts that correlate IPS/FW logs. ... Once you adopt an alert rule creation methodology possible within enVision and research the relevant message ID's, half the battle is done - also, testing various scenarios and thresholds is key. ...
  • Re: Workstation desktop occasionally "disappears"
    ... I'll start checking the logs whenever it happens to see if I ... can correlate it to something. ... > dragged a file's icon onto an Adobe Acrobat icon to convert the original ... > window, rather than dragging one icon onto the other. ...
  • Re: Workstation desktop occasionally "disappears"
    ... Is anything getting logged in the system or app logs when this happens? ... dragged a file's icon onto an Adobe Acrobat icon to convert the original ... It doesn't seem to correlate to any ... I've checked the Windows XP ...
  • Virus log
    ... Is there anything in W'ndows that logs all software installations? ... This would allow a user to check for activity that does not correlate to the ... And so if W'ndows does not have this feature then can a (Delphi) application ...