Some Custom ACS Reports

Published 03-12-2019 04:51 PM 911 Views
Microsoft

First published on TECHNET on Dec 09, 2009

Here are some ACS reports that I’ve written for various customers recently.  If you have ACS installed in the same Reporting Services instance as OpsMgr Reporting, then you can just import the attached Management Pack (CustomACSReports.xml).  Otherwise, you’ll need to import each .rdl file separately.

 

Here is a description of each report, along with some screenshots.

 

Event Search
This report allow the user to search for specific security events (selected from a pre-defined list). The user can select choose a specific server or search from events from all servers. The user can also specify search strings for the UserName or Description in the event. The report returns the top 100 events from the specified date range.

 

Authentication Failure Summary
This report queries the ACS database for Authentication Failure errors logged during a user specified time range (default is 1 week. The Event IDs queried for are Event ID 675 (Windows Server 2003) and Event ID 4771 (Windows Server 2008). The Events are grouped by the error code, and the error message and count for each error code are listed in a table. When the user clicks on one of the errors, the Authentication Failure Detail report is run for that error message.

 

Authentication Failure Detail
This report queries the ACS database for Authentication Failure errors with a specific error code logged during a user specified time range (default is 1 week. The Event IDs queried for are Event ID 675 (Windows Server 2003) and Event ID 4771 (Windows Server 2008). The Events are grouped by the IP Address and User Name, and the count for each is displayed in a table.

 

AD Object Changes
This report will show details of events related to changes in Active Directory. The report will query the ACS database for Event ID 566 / 5136 and show the Event Time, UserName, Domain Controller, Object Type, Object Name, accessed Properties, and the New Value of the property (Win2k8 only). The report also includes options to search for a specific string in the Object Name and/or Property Name.

 

Exchange AD Object Activity
This report shows events related to changes to Exchange Objects in Active Directory. The report will query the ACS database for Event ID 566 and 5136 within the specified time range, where the object name contains the string "CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=". The report groups the events by UserName, and shows the Event Time, Domain Controller, Object Type, Object Name, and accessed Properties. The report also includes an option to exclude changes made by computer accounts.

 

Account Lockout and Authentication Failure by User
This report accepts a date range, username, and domain and will list all occurrences of the following events for the specified user within the specified date range: Event 644 / 4740 (Account Lockout), Event 529 / 4625 (Unknown Username or Bad Password) , Event 675 / 4771 (Kerberos Pre-Authentication Failure), Event 680 / 4776 (NTLM Authentication Failure)

 

Account Lockout by User
This report accepts a date range, username, and domain and will list the time and computer name for all account lockout events (Event ID 644 / 4740) for the specified user within the specified date range.

 

Account Lockout Trends
This report accepts a date range and Domain name and will query for all Account Lockout events (Event ID 644 / 4740) within the specified date range and domain. The report contains charts which show average number of account lockouts for each hour of the day and each day of the week, and a trending chart which will show the number of account lockouts over the specified time range. The report also lists all of the lockouts in a table, grouped by Domain, User, Workstation, and Time.

 

Top 10 Accounts Failing Authentication
This report will query the ACS database for Authentication Failure events (Event ID 680 and 4776) within the specified time range. The report contains a table which will show the 10 user accounts with the most failures, grouped by Workstation and Error Code.

 

User Account Management Activity
This report will show the number of various account management events within a specified time range, grouped by domain. The events displayed are Accounts Changed (642,4738), Accounts Created (624,4720), Accounts Enabled (626,4722), Accounts Disabled(629,4725), Accounts Deleted (Event ID 630,4726), Names Changed (685,4781), Password Resets (628,4724), Accounts Unlocked (671,4767). Clicking on any of the numbers on the report will launch the "Automated Account Change Trends" report for more details.

 

ACS Events for Specified User
This report accepts a Username, Domain, and date range and will display all events where the specified User/Domain is in the TargetUser/TargetDomain, PrimaryUser/PrimaryDomain, ClientUser/ClientDomain, or HeaderUser/HeaderDomain fields. The domain list is pre-populated.

 

Event_Report_Basic
This report displays the Computer Name and Date/Time for a specific Event ID within a specified date range.

 

 

 

 

 

 

 

 

 

 

 

 

CustomACSReports.zip

%3CLINGO-SUB%20id%3D%22lingo-sub-365559%22%20slang%3D%22en-US%22%3ESome%20Custom%20ACS%20Reports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-365559%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3E%20First%20published%20on%20TECHNET%20on%20Dec%2009%2C%202009%20%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EHere%20are%20some%20ACS%20reports%20that%20I%E2%80%99ve%20written%20for%20various%20customers%20recently.%26nbsp%3B%20If%20you%20have%20ACS%20installed%20in%20the%20same%20Reporting%20Services%20instance%20as%20OpsMgr%20Reporting%2C%20then%20you%20can%20just%20import%20the%20attached%20Management%20Pack%20(CustomACSReports.xml).%26nbsp%3B%20Otherwise%2C%20you%E2%80%99ll%20need%20to%20import%20each%20.rdl%20file%20separately.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHere%20is%20a%20description%20of%20each%20report%2C%20along%20with%20some%20screenshots.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EEvent%20Search%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3EThis%20report%20allow%20the%20user%20to%20search%20for%20specific%20security%20events%20(selected%20from%20a%20pre-defined%20list).%20The%20user%20can%20select%20choose%20a%20specific%20server%20or%20search%20from%20events%20from%20all%20servers.%20The%20user%20can%20also%20specify%20search%20strings%20for%20the%20UserName%20or%20Description%20in%20the%20event.%20The%20report%20returns%20the%20top%20100%20events%20from%20the%20specified%20date%20range.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAuthentication%20Failure%20Summary%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20queries%20the%20ACS%20database%20for%20Authentication%20Failure%20errors%20logged%20during%20a%20user%20specified%20time%20range%20(default%20is%201%20week.%20The%20Event%20IDs%20queried%20for%20are%20Event%20ID%20675%20(Windows%20Server%202003)%20and%20Event%20ID%204771%20(Windows%20Server%202008).%20The%20Events%20are%20grouped%20by%20the%20error%20code%2C%20and%20the%20error%20message%20and%20count%20for%20each%20error%20code%20are%20listed%20in%20a%20table.%20When%20the%20user%20clicks%20on%20one%20of%20the%20errors%2C%20the%20Authentication%20Failure%20Detail%20report%20is%20run%20for%20that%20error%20message.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAuthentication%20Failure%20Detail%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20queries%20the%20ACS%20database%20for%20Authentication%20Failure%20errors%20with%20a%20specific%20error%20code%20logged%20during%20a%20user%20specified%20time%20range%20(default%20is%201%20week.%20The%20Event%20IDs%20queried%20for%20are%20Event%20ID%20675%20(Windows%20Server%202003)%20and%20Event%20ID%204771%20(Windows%20Server%202008).%20The%20Events%20are%20grouped%20by%20the%20IP%20Address%20and%20User%20Name%2C%20and%20the%20count%20for%20each%20is%20displayed%20in%20a%20table.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAD%20Object%20Changes%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20will%20show%20details%20of%20events%20related%20to%20changes%20in%20Active%20Directory.%20The%20report%20will%20query%20the%20ACS%20database%20for%20Event%20ID%20566%20%2F%205136%20and%20show%20the%20Event%20Time%2C%20UserName%2C%20Domain%20Controller%2C%20Object%20Type%2C%20Object%20Name%2C%20accessed%20Properties%2C%20and%20the%20New%20Value%20of%20the%20property%20(Win2k8%20only).%20The%20report%20also%20includes%20options%20to%20search%20for%20a%20specific%20string%20in%20the%20Object%20Name%20and%2For%20Property%20Name.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EExchange%20AD%20Object%20Activity%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20shows%20events%20related%20to%20changes%20to%20Exchange%20Objects%20in%20Active%20Directory.%20The%20report%20will%20query%20the%20ACS%20database%20for%20Event%20ID%20566%20and%205136%20within%20the%20specified%20time%20range%2C%20where%20the%20object%20name%20contains%20the%20string%20%22CN%3DMicrosoft%20Exchange%2CCN%3DServices%2CCN%3DConfiguration%2CDC%3D%22.%20The%20report%20groups%20the%20events%20by%20UserName%2C%20and%20shows%20the%20Event%20Time%2C%20Domain%20Controller%2C%20Object%20Type%2C%20Object%20Name%2C%20and%20accessed%20Properties.%20The%20report%20also%20includes%20an%20option%20to%20exclude%20changes%20made%20by%20computer%20accounts.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAccount%20Lockout%20and%20Authentication%20Failure%20by%20User%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20accepts%20a%20date%20range%2C%20username%2C%20and%20domain%20and%20will%20list%20all%20occurrences%20of%20the%20following%20events%20for%20the%20specified%20user%20within%20the%20specified%20date%20range%3A%20Event%20644%20%2F%204740%20(Account%20Lockout)%2C%20Event%20529%20%2F%204625%20(Unknown%20Username%20or%20Bad%20Password)%20%2C%20Event%20675%20%2F%204771%20(Kerberos%20Pre-Authentication%20Failure)%2C%20Event%20680%20%2F%204776%20(NTLM%20Authentication%20Failure)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAccount%20Lockout%20by%20User%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20accepts%20a%20date%20range%2C%20username%2C%20and%20domain%20and%20will%20list%20the%20time%20and%20computer%20name%20for%20all%20account%20lockout%20events%20(Event%20ID%20644%20%2F%204740)%20for%20the%20specified%20user%20within%20the%20specified%20date%20range.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAccount%20Lockout%20Trends%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3EThis%20report%20accepts%20a%20date%20range%20and%20Domain%20name%20and%20will%20query%20for%20all%20Account%20Lockout%20events%20(Event%20ID%20644%20%2F%204740)%20within%20the%20specified%20date%20range%20and%20domain.%20The%20report%20contains%20charts%20which%20show%20average%20number%20of%20account%20lockouts%20for%20each%20hour%20of%20the%20day%20and%20each%20day%20of%20the%20week%2C%20and%20a%20trending%20chart%20which%20will%20show%20the%20number%20of%20account%20lockouts%20over%20the%20specified%20time%20range.%20The%20report%20also%20lists%20all%20of%20the%20lockouts%20in%20a%20table%2C%20grouped%20by%20Domain%2C%20User%2C%20Workstation%2C%20and%20Time.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ETop%2010%20Accounts%20Failing%20Authentication%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20will%20query%20the%20ACS%20database%20for%20Authentication%20Failure%20events%20(Event%20ID%20680%20and%204776)%20within%20the%20specified%20time%20range.%20The%20report%20contains%20a%20table%20which%20will%20show%20the%2010%20user%20accounts%20with%20the%20most%20failures%2C%20grouped%20by%20Workstation%20and%20Error%20Code.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EUser%20Account%20Management%20Activity%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20will%20show%20the%20number%20of%20various%20account%20management%20events%20within%20a%20specified%20time%20range%2C%20grouped%20by%20domain.%20The%20events%20displayed%20are%20Accounts%20Changed%20(642%2C4738)%2C%20Accounts%20Created%20(624%2C4720)%2C%20Accounts%20Enabled%20(626%2C4722)%2C%20Accounts%20Disabled(629%2C4725)%2C%20Accounts%20Deleted%20(Event%20ID%20630%2C4726)%2C%20Names%20Changed%20(685%2C4781)%2C%20Password%20Resets%20(628%2C4724)%2C%20Accounts%20Unlocked%20(671%2C4767).%20Clicking%20on%20any%20of%20the%20numbers%20on%20the%20report%20will%20launch%20the%20%22Automated%20Account%20Change%20Trends%22%20report%20for%20more%20details.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EACS%20Events%20for%20Specified%20User%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20accepts%20a%20Username%2C%20Domain%2C%20and%20date%20range%20and%20will%20display%20all%20events%20where%20the%20specified%20User%2FDomain%20is%20in%20the%20TargetUser%2FTargetDomain%2C%20PrimaryUser%2FPrimaryDomain%2C%20ClientUser%2FClientDomain%2C%20or%20HeaderUser%2FHeaderDomain%20fields.%20The%20domain%20list%20is%20pre-populated.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EEvent_Report_Basic%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%20This%20report%20displays%20the%20Computer%20Name%20and%20Date%2FTime%20for%20a%20specific%20Event%20ID%20within%20a%20specified%20date%20range.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20559px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86789i04BB4D50A18F2336%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20533px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86790iC974721ACAED423D%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20515px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86792iB0A049527C82A54B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20742px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86794i4867F46ED6558A27%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20925px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86796i298CCB3DE14B5DEB%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86798i0A3E71FD960C48FA%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86800i66FC8DEBA454001B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86802i626DCC9A23C9984A%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86803i3351E64DA7F66FB1%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86805iAEB81F27BC774A95%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F86806iBF7B4D8DB31D0514%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fmsdnshared.blob.core.windows.net%2Fmedia%2FTNBlogsFS%2Fprod.evol.blogs.technet.com%2Ftelligent.evolution.components.attachments%2F01%2F6699%2F00%2F00%2F03%2F29%2F94%2F93%2FCustomACSReports.zip%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%20CustomACSReports.zip%20%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-365559%22%20slang%3D%22en-US%22%3E%3CP%3EFirst%20published%20on%20TECHNET%20on%20Dec%2009%2C%202009%20Here%20are%20some%20ACS%20reports%20that%20I%E2%80%99ve%20written%20for%20various%20customers%20recently.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-365559%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EJimmyHarper%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Version history
Last update:
‎Feb 20 2020 10:38 AM
Updated by: