You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻求Server 2012环境下AD用户登录实时监控自动更新脚本方案

Got it, let's tackle this AD user login monitoring need you have. Here are a few practical, auto-updating solutions that fit your requirement of displaying real-time login events like a live log on a monitor:

方案1:实时PowerShell监控脚本(轻量、无需额外工具)

This is my go-to for quick, customizable monitoring since it uses built-in Windows tools. The script will listen for new successful login events (Event ID 4624) in the Security log, format the key details, and output them in real-time—perfect for a full-screen PowerShell window on your monitor.

Here’s the script:

# Real-time AD User Login Monitor Script
$eventFilter = @"
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">*[System[EventID=4624 and (EventData[Data[@Name='LogonType']='2' or EventData[Data[@Name='LogonType']='10'])]]</Select>
  </Query>
</QueryList>
"@

# Monitor and display events in real-time
Get-WinEvent -FilterXml $eventFilter -Wait | ForEach-Object {
    $username = $_.Properties[5].Value
    $deviceName = $_.Properties[11].Value
    $loginTime = $_.TimeCreated.ToString("yyyy-MM-dd HH:mm:ss.fff")
    $loginType = switch ($_.Properties[8].Value) {
        2 { "Local Interactive Login" }
        10 { "Remote Interactive (RDP) Login" }
        default { "Other Login Type: $($_.Properties[8].Value)" }
    }

    # Output to console with color coding for readability
    Write-Host "[$loginTime] USER: $username | DEVICE: $deviceName | EVENT: Successful $loginType" -ForegroundColor Cyan
}

Tips for this script:

  • To save logs to a file while displaying them live, add | Tee-Object -FilePath "C:\Logs\AD_Login_Monitor.log" at the end of the Get-WinEvent line.
  • Run this from a domain controller or a machine with permissions to read domain security logs (use a service account with log read access).
  • Full-screen the PowerShell window on your monitor for a clean, log-like display.

方案2:Event Viewer自定义实时视图(零代码,开箱即用)

If you prefer a GUI without writing scripts, Windows Event Viewer can be configured to show real-time login events:

  1. Open Event Viewer → Right-click Custom Views → Select Create Custom View.
  2. In the filter:
    • Check By log → Select Windows Logs > Security.
    • Check By event ID → Enter 4624.
    • (Optional) Add a filter for Logon Type: Go to the XML tab and modify the query to include and (EventData[Data[@Name='LogonType']='2' or EventData[Data[@Name='LogonType']='10']]) (like in the PowerShell script).
  3. Click OK, name your view (e.g., "AD User Real-Time Logins").
  4. Right-click the new view → Go to View → Enable Refresh Automatically.
  5. Maximize the Event Viewer window on your monitor—new login events will appear in real-time.

Pro tip:

Customize the columns to show only what you need: Right-click the column header → Add/Remove Columns → Include "Time Created", "User Name", "Computer", and "Logon Type".

方案3:Python GUI监控工具(更 polished 的可视化界面)

If you want a more user-friendly, dedicated display, a simple Python script with a GUI can do the trick. It pulls events in real-time and shows them in a scrollable text box.

First, install the required library:

pip install pywin32

Then use this script:

import win32evtlog
import time
import threading
from tkinter import Tk, Text, END, Scrollbar, Label

def monitor_login_events():
    # Replace with your domain controller name if monitoring remotely
    server_name = "localhost"
    log_source = "Security"
    event_handle = win32evtlog.OpenEventLog(server_name, log_source)
    read_flags = win32evtlog.EVENTLOG_FORWARDS_READ | win32evtlog.EVENTLOG_SEQUENTIAL_READ

    while True:
        events = win32evtlog.ReadEventLog(event_handle, read_flags, 0)
        if events:
            for event in events:
                if event.EventID == 4624:
                    # Extract key details from event inserts
                    user = event.StringInserts[5]
                    device = event.StringInserts[11]
                    timestamp = event.TimeGenerated.Format("%Y-%m-%d %H:%M:%S.%f")[:-3]
                    logon_type = event.StringInserts[8]
                    type_desc = "Local Login" if logon_type == "2" else "Remote (RDP) Login" if logon_type == "10" else f"Type {logon_type}"
                    
                    log_line = f"[{timestamp}] USER: {user} | DEVICE: {device} | EVENT: Successful {type_desc}\n"
                    log_box.insert(END, log_line)
                    log_box.see(END)  # Auto-scroll to latest entry
                    root.update()
        time.sleep(1)

# Set up GUI window
root = Tk()
root.title("AD User Login Monitor")
root.geometry("1000x600")

header_label = Label(root, text="Real-Time AD User Login Events", font=("Arial", 14, "bold"))
header_label.pack(pady=10)

log_box = Text(root, wrap="word", font=("Consolas", 10))
scrollbar = Scrollbar(root, command=log_box.yview)
log_box.configure(yscrollcommand=scrollbar.set)

log_box.pack(side="left", fill="both", expand=True, padx=10, pady=10)
scrollbar.pack(side="right", fill="y")

# Start monitoring in a background thread
monitor_thread = threading.Thread(target=monitor_login_events)
monitor_thread.daemon = True
monitor_thread.start()

root.mainloop()

Bonus:

You can package this script into a standalone EXE using pyinstaller so you don’t need Python installed on the monitor machine:

pyinstaller --onefile --windowed login_monitor.py

Key Notes for All Solutions:

  • Permissions: Ensure the running account has read access to the domain's Security logs (domain admin or a dedicated monitoring account works best).
  • Filtering: Adjust the event IDs/logon types to match your needs (e.g., exclude service accounts or specific login methods).
  • Persistence: For 24/7 monitoring, add the script/EXE to Windows Task Scheduler to run on startup.

内容的提问来源于stack exchange,提问作者NickCarlt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:07:54