No user or LDAP information is being shown in reports when using DCInterface.

Article:TECH134911  |  Created: 2010-01-15  |  Updated: 2012-05-16  |  Article URL http://www.symantec.com/docs/TECH134911
Article Type
Technical Solution


Issue



No user or LDAP information is being shown in reports when using DCInterface.

Symptoms
When viewing a report the Login Name, Full Name, and department are blank.

When trying to create or edit a policy, no LDAP related information is available.
The test of the LDAP configuration on the Authentication tab is successful.
There are no current errors in the DCInterface error.log file.

 


Cause



DCInterface queries the DC event logs for successful login events.  If the DC is not configured to log these events then no user login information will be retrieved.


Solution



Checked the Domain Controllers Security log and found no Logon/off events logged in the category of Logon/logoff. DCInterface is looking for the following Event IDs into the Security log:

  • 540
  • 672
  • 4624
  • 4768
  •  

The first two events pertain to W2K3S while the second two events pertain to W2K8S

If no logon/off events are found in the Security log they can be enable in the Domain Controller Security Policy editor.

Windows 2003 sp2

1. Go to Administrative Tools/ DC Security Policies/ Local Policies/ Audit Policy/ Audit Account/ Logon events.

2. Edit and change to log success.

3. Save.

Windows 2008, Windows 2008 R2 

1. Go to Administrative Tools->Group Policy Management, right click and edit the default domain controller policy,

2. Browse to Computer Configuration->Policies->Windows Settings->Security Settings->Local Policies->Audit Policy->Audit Account Login Events.

3. Edit and change to log success.

4. Save.





References
http://support.microsoft.com/kb/828857

http://www.windowsecurity.com/articles/Windows-Active-Directory-Auditing.html




Legacy ID



2010071509463554


Article URL http://www.symantec.com/docs/TECH134911


Terms of use for this information are found in Legal Notices