Home Section_sub_break Using GoToAssist Section_sub_break Technical Support
Icon_discussion_forum_small Alerts - Login Failures
I am new to GoToManage and wondering how I set up an event to notify of failed logins from my server event viewers. A...
Icon_post
5
Icon_person
Jon Stratford
Icon_time
08/02/2011 at 21:12
Reply
2 posts
Joined: 07/08/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 07/12/2011 at 11:57

I am new to GoToManage and wondering how I set up an event to notify of failed logins from my server event viewers. A couple things we are looing for are failed SQL Database attempts and also RDP. I don’t see anything like this in the standard events to choose from.

13 posts
Joined: 03/31/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 07/15/2011 at 00:43

Hi Rick,
if the eventid is collected in the Logs application, you can set an custom Alert indicating the eventid. in this way you should get an alert on every failed login.

2 posts
Joined: 07/01/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 07/21/2011 at 10:16

Thanks Thomas. Can you please elaborate? I.e. I’ve tried searching for EventCode=529 and don’t get any results, even though I know that’s inside the security log of the server.

Thanks!

13 posts
Joined: 03/31/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 07/22/2011 at 00:59

Hi Jeff,
Have you check if the Security Event logs are collected in gotomanage? If not you should configure the Crawler WMI Event login to collect Event logs Security Audit Failure.
If you then Search in the log files source::win_event_log:Security 529 you should then get a list whit all Events 529. On good result try on the Alert Application
Regards,
Thomas

2 posts
Joined: 07/01/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 08/02/2011 at 07:37

Thanks Thomas. Forgive me, but where do I configure the WMI Event Login to collect logs for Security events? When I go into configure crawler, It’s not clear to me where that is. Thanks!

- Jeff

2 posts
Joined: 01/11/11
Empty_star Empty_star Empty_star Empty_star
Icon_time 08/02/2011 at 21:12

Hi Jeff,

Go to "monitoring>crawlers and select your crawler. If you are using the default schedule, the “monitor windows servers” schedule has the wmi_event_log plugin. You will need to click on that schedule and click on the “set parameters” option. I set mine from “error” to “security audit success”. After the next scheduled run time for the plugin you should be able to use the share it for “all logons by users”

Reply