3.0
2018-12-13T08:10:01Z
Templates Active Directory
ActiveDirectory - User Log
ActiveDirectory - User Log
Templates Active Directory
-
accountExpires
2
0
windows.activedirectory.users.accountExpires
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
ads_uf_accountdisable
2
0
windows.activedirectory.users.ads_uf_accountdisable
0
90
365
0
3
0
0
0
0
1
0
0
The user account is disabled.
0
Service state
-
ads_uf_dont_expire_passwd
2
0
windows.activedirectory.users.ads_uf_dont_expire_passwd
0
90
365
0
3
0
0
0
0
1
0
0
The password for this account will never expire.
0
Service state
-
ads_uf_dont_require_preauth
2
0
windows.activedirectory.users.ads_uf_dont_require_preauth
0
90
365
0
3
0
0
0
0
1
0
0
This account does not require Kerberos pre-authentication for logon.
0
Service state
-
ads_uf_encrypted_text_password_allowed
2
0
windows.activedirectory.users.ads_uf_encrypted_text_password_allowed
0
90
365
0
3
0
0
0
0
1
0
0
This account does not require Kerberos pre-authentication for logon.
0
Service state
-
ads_uf_homedir_required
2
0
windows.activedirectory.users.ads_uf_homedir_required
0
90
365
0
3
0
0
0
0
1
0
0
The home directory is required.
0
Service state
-
ads_uf_interdomain_trust_account
2
0
windows.activedirectory.users.ads_uf_interdomain_trust_account
0
90
365
0
3
0
0
0
0
1
0
0
This is a permit to trust account for a system domain that trusts other domains.
0
Service state
-
ads_uf_lockout
2
0
windows.activedirectory.users.ads_uf_lockout
0
90
365
0
3
0
0
0
0
1
0
0
The account is currently locked out.
0
Service state
-
ads_uf_mns_logon_account
2
0
windows.activedirectory.users.ads_uf_mns_logon_account
0
90
365
0
3
0
0
0
0
1
0
0
This is an MNS logon account.
0
Service state
-
ads_uf_normal_account
2
0
windows.activedirectory.users.ads_uf_normal_account
0
90
365
0
3
0
0
0
0
1
0
0
This is a default account type that represents a typical user.
0
Service state
-
ads_uf_not_delegated
2
0
windows.activedirectory.users.ads_uf_not_delegated
0
90
365
0
3
0
0
0
0
1
0
0
The security context of the user will not be delegated to a service even if the service account is set as trusted for Kerberos delegation.
0
Service state
-
ads_uf_passwd_cant_change
2
0
windows.activedirectory.users.ads_uf_passwd_cant_change
0
90
365
0
3
0
0
0
0
1
0
0
The user cannot change the password.
0
Service state
-
ads_uf_passwd_notreqd
2
0
windows.activedirectory.users.ads_uf_passwd_notreqd
0
90
365
0
3
0
0
0
0
1
0
0
No password is required.
0
Service state
-
ads_uf_password_expired
2
0
windows.activedirectory.users.ads_uf_password_expired
0
90
365
0
3
0
0
0
0
1
0
0
The user password has expired. This flag is created by the system using data from the Pwd-Last-Set attribute and the domain policy.
0
Service state
-
ads_uf_script
2
0
windows.activedirectory.users.ads_uf_script
0
90
365
0
3
0
0
0
0
1
0
0
The logon script is executed.
0
Service state
-
ads_uf_server_trust_account
2
0
windows.activedirectory.users.ads_uf_server_trust_account
0
90
365
0
3
0
0
0
0
1
0
0
This is a computer account for a system backup domain controller that is a member of this domain.
0
Service state
-
ads_uf_smartcard_required
2
0
windows.activedirectory.users.ads_uf_smartcard_required
0
90
365
0
3
0
0
0
0
1
0
0
The user must log on using a smart card.
0
Service state
-
ads_uf_temp_duplicate_account
2
0
windows.activedirectory.users.ads_uf_temp_duplicate_account
0
90
365
0
3
0
0
0
0
1
0
0
This is an account for users whose primary account is in another domain. This account provides user access to this domain, but not to any domain that trusts this domain. Also known as a local user account.
0
Service state
-
ads_uf_trusted_for_delegation
2
0
windows.activedirectory.users.ads_uf_trusted_for_delegation
0
90
365
0
3
0
0
0
0
1
0
0
The service account (user or computer account), under which a service runs, is trusted for Kerberos delegation. Any such service can impersonate a client requesting the service.
0
Service state
-
ads_uf_trusted_to_authenticate_for_delegation
2
0
windows.activedirectory.users.ads_uf_trusted_to_authenticate_for_delegation
0
90
365
0
3
0
0
0
0
1
0
0
The account is enabled for delegation. This is a security-sensitive setting; accounts with this option enabled should be strictly controlled. This setting enables a service running under the account to assume a client identity and authenticate as that user to other remote servers on the network.
0
Service state
-
ads_uf_use_des_key_only
2
0
windows.activedirectory.users.ads_uf_use_des_key_only
0
90
365
0
3
0
0
0
0
1
0
0
Restrict this principal to use only Data Encryption Standard (DES) encryption types for keys.
0
Service state
-
ads_uf_workstation_trust_account
2
0
windows.activedirectory.users.ads_uf_workstation_trust_account
0
90
365
0
3
0
0
0
0
1
0
0
This is a computer account for a computer that is a member of this domain.
0
Service state
-
badPasswordTime
2
0
windows.activedirectory.users.badPasswordTime
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
Passwortfehlzähler
2
0
windows.activedirectory.users.badPwdCount
0
90
365
0
3
0
0
0
0
1
0
0
0
-
distinguishedName
2
0
windows.activedirectory.users.distinguishedName
0
90
0
0
4
0
0
0
0
1
0
0
0
-
lastLogoff
2
0
windows.activedirectory.users.lastLogoff
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
lastLogon
2
0
windows.activedirectory.users.lastLogon
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
lastLogonTimestamp
2
0
windows.activedirectory.users.lastLogonTimestamp
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
lockoutTime
2
0
windows.activedirectory.users.lockoutTime
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
logonCount
2
0
windows.activedirectory.users.logonCount
0
90
365
0
3
0
0
0
0
1
0
0
0
-
pwdLastSet
2
0
windows.activedirectory.users.pwdLastSet
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
sAMAccountName
2
0
windows.activedirectory.users.sAMAccountName
0
90
0
0
4
0
0
0
0
1
0
0
0
-
whenChanged
2
0
windows.activedirectory.users.whenChanged
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
-
whenCreated
2
0
windows.activedirectory.users.whenCreated
0
90
365
0
3
unixtime
0
0
0
0
1
0
0
0
({ActiveDirectory - User Log:windows.activedirectory.users.ads_uf_accountdisable.last(0)}>0)
Benutzer {HOST.NAME} wurde deaktiviert
0
0
0
({ActiveDirectory - User Log:windows.activedirectory.users.lockoutTime.change()}<0) and ({ActiveDirectory - User Log:windows.activedirectory.users.lockoutTime.last(0)}=0)
Benutzer {HOST.NAME} wurde freigeschaltet
1
1
0
({ActiveDirectory - User Log:windows.activedirectory.users.lockoutTime.last(0)}>0)
Benutzer {HOST.NAME} wurde gesperrt
0
1
0
Service state
0
Down
1
Up