Troubleshooting

1. How to check if the audit polices and the security log settings have been applied on the monitored computers:

Log in to any computer with domain IT admin privileges → Run Command Prompt as an administrator → Type gpresult /S <monitored computer> /F /H <file name>.HTML → Navigate to C:\Users\<logged in user><file name.HTML> to check if all the audit policy settings and security logs settings are in place.

2. How to check if object-level auditing settings are in place:

Refer to section four (4) found in this document.

3. How to verify that the events are present in the monitored computers:

Log in to any computer with domain admin privileges → Go to Run, and type eventvwr.msc → Right-click on Event Viewer, and connect to the target computer → Check if the corresponding event numbers are present.

我们的客户