Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Event 528 as SNMP trap

Status
Not open for further replies.

bmquiroz

IS-IT--Management
Sep 26, 2003
207
US
Hello all,

Trying to figure out how to configure (Event 528, Logon Type 10, Logon Process User32) as an SNMP trap. I am using "Event to Trap Translator" and I would like to send successful "user" logins as an SNMP trap to my NMS machine. The problem is that under "Event to Trap Translator" it shows Event 528 without variables i.e. no logon type, logon process, etc. This logs every sys logon event, services and all. I only want to monitor user local logins. How can accomplish this? Registry hack?

Thanks.

-Sip
 
You're out of luck on this point, Im afraid. Event to Trap is pretty basic. Any filtering you want to do will need to be done on the SNMP trap receiver end. What exactly do you want to do? Do you want to real-time monitor user logins or do you just want a report on the logins?

For reporting you can use Log Parser to strip out the relevant records either from the SNMP log or from the event log itself.
 
Hi Castor,

Thanks for the reply. I would like to monitor logins in real time via SNMP trap to my NMS machine. The NMS machine would then generate a notification based on event. Should I try a syslog service instead?

Thanks.

-Sip
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top