Lockout Account More Details

What is a one sentence summary of your feature request?

When we pull lockout reports It would be nice to get Workstation Details in the “User Account Locks and Unlock” report

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Netwrix generates reports based on event logs—for example, event IDs 4740 and 4767 are included. However, the “Caller Computer Name” field is not captured in the report, even though it’s available in the original event log.

How do you currently solve the challenges you have by not having this feature?

I logged into one of the Domain Controllers and filtered for event IDs 4740 and 4767, which provided the information I needed. However, it would be much more efficient to retrieve this data from a centralized source rather than having to log into the DC server each time.

Netwrix is intended to reduce the need for direct access to servers, and ideally, we should be able to pull this information directly from it. While Netwrix offers extensive functionality, it still has some limitations—especially when it comes to retrieving the same event data that’s readily available in Event Viewer. This is an area where we should expect more streamlined access.

Hi Jason,

Thanks for the detailed write-up — this is a genuinely useful request, and you’re right that pulling the originating workstation from a central source beats logging into each DC.

While we look at surfacing the “Caller Computer Name” field in the User Account Locks and Unlock report itself, I wanted to point you to a tool that may already cover what you need in the meantime: our free Account Lockout Examiner.

Free Account Lockout Tool | Netwrix

It’s purpose-built for exactly this scenario — it identifies where a lockout originated, including the source workstation/host responsible for the bad password attempts, so you can trace lockouts back to their origin without remoting into the domain controllers. For lockout troubleshooting specifically, it tends to give richer origin detail than the event-log-based report does today.

Would that work for your use case? If you give it a try, I’d be interested to hear whether it gets you the workstation context you’re after.

Best regards,

Denis Antropov

1 Like