Jan 30 2020 03:45 PM
Jan 30 2020 03:45 PM
Hi all,
I want to monitor my NPS logs to see when VPN connections are made.
I can see the requests (packet-type 1) contain the username of the user making the request but the accept and reject records (packet-types 2 and 3) do not contain a username, nor any other information I could use to match the request to the accept/reject record.
The ID's do appear consecutively, but could I trust this is always the case? Is there perhaps another setting to enable more information in the logs?
cheers
jc
Feb 02 2020 01:23 PM
@DeletedNPS has a custom view in the event logs that shows successful and failed login attempts, complete with the policies that were used. Does this give you the info you need? Which logs are you trying to correlate?
Feb 26 2020 08:04 PM
Mar 05 2020 05:47 AM
Hi @Deleted
Sorry for delayed reply. It looks like you're using the Accounting logs. Could you use the built in Event Logs to get the information you need?
Thinking rather than correlating events, this might be an easier way to obtain the information you require?