Comments (2)
Will be added in 2.0.10
from pswinreporting.
This is the final definition that covers Create/Delete/Modify/Move.
ADOrganizationalUnitChangesDetailed = [ordered] @{
Enabled = $true
OUEventsModify = @{
Enabled = $true
Events = 5136, 5137, 5139, 5141
LogName = 'Security'
Filter = @{
'ObjectClass' = 'organizationalUnit'
}
Functions = @{
'OperationType' = 'ConvertFrom-OperationType'
}
Fields = [ordered] @{
'Computer' = 'Domain Controller'
'Action' = 'Action'
'OperationType' = 'Action Detail'
'Who' = 'Who'
'Date' = 'When'
'ObjectDN' = 'Organizational Unit'
'AttributeLDAPDisplayName' = 'Field Changed'
'AttributeValue' = 'Field Value'
#'OldObjectDN' = 'OldObjectDN'
#'NewObjectDN' = 'NewObjectDN'
# Common Fields
'RecordID' = 'Record ID'
'ID' = 'Event ID'
'GatheredFrom' = 'Gathered From'
'GatheredLogName' = 'Gathered LogName'
}
Overwrite = @{
'Action Detail#1' = 'Action', 'A directory service object was created.', 'Organizational Unit Created'
'Action Detail#2' = 'Action', 'A directory service object was deleted.', 'Organizational Unit Deleted'
'Action Detail#3' = 'Action', 'A directory service object was moved.', 'Organizational Unit Moved'
#'Organizational Unit' = 'Action', 'A directory service object was moved.', 'OldObjectDN'
#'Field Changed' = 'Action', 'A directory service object was moved.', ''
#'Field Value' = 'Action', 'A directory service object was moved.', 'NewObjectDN'
}
# This Overwrite works in a way where you can swap one value with another value from another field within same Event
# It's useful if you have an event that already has some fields used but empty and you wnat to utilize them
# for some content
OverwriteByField = @{
'Organizational Unit' = 'Action', 'A directory service object was moved.', 'OldObjectDN'
#'Field Changed' = 'Action', 'A directory service object was moved.', ''
'Field Value' = 'Action', 'A directory service object was moved.', 'NewObjectDN'
}
SortBy = 'Record ID'
Descending = $false
IgnoreWords = @{}
}
}
from pswinreporting.
Related Issues (20)
- RAM issue HOT 8
- I do not understand how to use SQL HOT 6
- Error - no events were found that match for version 1.8.1.3 HOT 1
- Error - no events were found that match for version 1.8.1.5 HOT 6
- Domain Controller requirements? HOT 1
- PSWinReportingV1 - Error if log path doesn't exists
- [-] Event Log Error on <server>: The RPC server is unavailable
- Unable to install onto AzureVM HOT 2
- report highlighting with ad in german language HOT 18
- missing username in AD UserLockout events HOT 9
- Event ID 4722 (enabled), 4725 (disabled), 4726 (deleted) are not visible in the output file HOT 1
- ADUserChangesDetailed Event ID 5139 reporting issues HOT 4
- NTLMv1 request
- Charts are broken after running Find-Events HOT 2
- Using Loghost / ForwardedEvents
- Report generation taking a long time anywhere from 6 hours plus. HOT 4
- Logo Setup
- MS SQL Output: Error occured (Send-SqlInsert) HOT 2
- Not sending to Teams HOT 9
- Type of table keys HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from pswinreporting.