Unsecured LDAP Binds

Hi Team. 

We are going through a test run of Change Auditor. I am trying to report / alert on Unsecure LDAP binds that might be happening in our environment. The EventID is 2889 in the Directory Service. How can i search for a specific EventID? Still learning so maybe i am missing where i can supply this in the What on the search. 

We are running version 7.2 at the moment

Thanks in advance

Parents
  • Change Auditor doesn't capture native events / event IDs as it generates its own more concise events.

    Each of the various categories of events and the specific events generated can be found here under the Reference Guide section.

    Note that each of the categories (for example Active Directory, Windows File Servers, SQL) typically represents a separate license that needs to be purchased.

Reply
  • Change Auditor doesn't capture native events / event IDs as it generates its own more concise events.

    Each of the various categories of events and the specific events generated can be found here under the Reference Guide section.

    Note that each of the categories (for example Active Directory, Windows File Servers, SQL) typically represents a separate license that needs to be purchased.

Children