Auditor NTLM Log

A customer has set NTLM sign-ins via the event log on the DC to „audit all“. The logs also show up in Event Viewer. Can this be analyzed with Netwrix? In other words, can it be queried and shown in the console? The event IDs are 4032.

Microsoft-Windows-NTLM/Operational

Also in general: How can I collect logs that aren’t in the Application, Security, or System log?

Hello Julian,

If Netwrix Auditor is licensed for the Windows Server data source, then you have access to an external tool called Netwrix Auditor Event Log Manager. This tool allows you to audit any Windows Event log that you want to.

That tool has some built in collectors and you can add any custom collector you wish. You can find more about this tool at Event Log Manager | Netwrix Product Documentation.

If you have any questions on getting the tool set up, just let me know. I’ll be happy to help.

If you do not have the Windows Server data source, you can always try a self-service trial of it or contact your Account Manager and they can get you a trial license for the tool.

Michael Purdin
Manager, Technical Support Engineering

Thanks for the reply. I just tested it in the lab, but it’s not quite what the customer would expect.

The Event Logs manager collects data from servers. Okay. But the display is still not in the Netwrix console—instead it’s only available as an export in an evtx format. That creates a media break for us.

Ideal scenario: The event IDs data should be viewable, filterable, and searchable via the Netwrix console. Possibly even with an alert. So basically like any other event. Is there a solution for that?

Julian,

You can actually get the data into the Netwrix Auditor Console. While you won’t be able to Search for the data, you can get the data to show up under Reports.

When you are adding a filter, you want to ensure that the “Write to” option is set to “Both”. If you do only the Long-Term Archive, then you just get the etvx files.

In addition, you should go to the Audit Database tab and ensure that “Write data to the Audit Database and enable reports” is checked.

Once you change those settings, any future data collected will be able to be retreived from the Reports folder in the main console.

It will be under Reports–>Windows Server–>Event Log

This won’t allow you to create alerts as you can only do that with data that you can search with but you can do alerts directly in Event Log Manager. It’s set up the same way as the filters, it’s just using a different button on the main screen.

Give this a try and see if this works for you. I’m happy to answer any additional questions you may have.

Michael Purdin
Manager, Technical Support Engineering