寻求Server 2012环境下AD用户登录实时监控自动更新脚本方案
Got it, let's tackle this AD user login monitoring need you have. Here are a few practical, auto-updating solutions that fit your requirement of displaying real-time login events like a live log on a monitor:
方案1:实时PowerShell监控脚本(轻量、无需额外工具)
This is my go-to for quick, customizable monitoring since it uses built-in Windows tools. The script will listen for new successful login events (Event ID 4624) in the Security log, format the key details, and output them in real-time—perfect for a full-screen PowerShell window on your monitor.
Here’s the script:
# Real-time AD User Login Monitor Script $eventFilter = @" <QueryList> <Query Id="0" Path="Security"> <Select Path="Security">*[System[EventID=4624 and (EventData[Data[@Name='LogonType']='2' or EventData[Data[@Name='LogonType']='10'])]]</Select> </Query> </QueryList> "@ # Monitor and display events in real-time Get-WinEvent -FilterXml $eventFilter -Wait | ForEach-Object { $username = $_.Properties[5].Value $deviceName = $_.Properties[11].Value $loginTime = $_.TimeCreated.ToString("yyyy-MM-dd HH:mm:ss.fff") $loginType = switch ($_.Properties[8].Value) { 2 { "Local Interactive Login" } 10 { "Remote Interactive (RDP) Login" } default { "Other Login Type: $($_.Properties[8].Value)" } } # Output to console with color coding for readability Write-Host "[$loginTime] USER: $username | DEVICE: $deviceName | EVENT: Successful $loginType" -ForegroundColor Cyan }
Tips for this script:
- To save logs to a file while displaying them live, add
| Tee-Object -FilePath "C:\Logs\AD_Login_Monitor.log"at the end of theGet-WinEventline. - Run this from a domain controller or a machine with permissions to read domain security logs (use a service account with log read access).
- Full-screen the PowerShell window on your monitor for a clean, log-like display.
方案2:Event Viewer自定义实时视图(零代码,开箱即用)
If you prefer a GUI without writing scripts, Windows Event Viewer can be configured to show real-time login events:
- Open Event Viewer → Right-click Custom Views → Select Create Custom View.
- In the filter:
- Check By log → Select Windows Logs > Security.
- Check By event ID → Enter
4624. - (Optional) Add a filter for Logon Type: Go to the XML tab and modify the query to include
and (EventData[Data[@Name='LogonType']='2' or EventData[Data[@Name='LogonType']='10']])(like in the PowerShell script).
- Click OK, name your view (e.g., "AD User Real-Time Logins").
- Right-click the new view → Go to View → Enable Refresh Automatically.
- Maximize the Event Viewer window on your monitor—new login events will appear in real-time.
Pro tip:
Customize the columns to show only what you need: Right-click the column header → Add/Remove Columns → Include "Time Created", "User Name", "Computer", and "Logon Type".
方案3:Python GUI监控工具(更 polished 的可视化界面)
If you want a more user-friendly, dedicated display, a simple Python script with a GUI can do the trick. It pulls events in real-time and shows them in a scrollable text box.
First, install the required library:
pip install pywin32
Then use this script:
import win32evtlog import time import threading from tkinter import Tk, Text, END, Scrollbar, Label def monitor_login_events(): # Replace with your domain controller name if monitoring remotely server_name = "localhost" log_source = "Security" event_handle = win32evtlog.OpenEventLog(server_name, log_source) read_flags = win32evtlog.EVENTLOG_FORWARDS_READ | win32evtlog.EVENTLOG_SEQUENTIAL_READ while True: events = win32evtlog.ReadEventLog(event_handle, read_flags, 0) if events: for event in events: if event.EventID == 4624: # Extract key details from event inserts user = event.StringInserts[5] device = event.StringInserts[11] timestamp = event.TimeGenerated.Format("%Y-%m-%d %H:%M:%S.%f")[:-3] logon_type = event.StringInserts[8] type_desc = "Local Login" if logon_type == "2" else "Remote (RDP) Login" if logon_type == "10" else f"Type {logon_type}" log_line = f"[{timestamp}] USER: {user} | DEVICE: {device} | EVENT: Successful {type_desc}\n" log_box.insert(END, log_line) log_box.see(END) # Auto-scroll to latest entry root.update() time.sleep(1) # Set up GUI window root = Tk() root.title("AD User Login Monitor") root.geometry("1000x600") header_label = Label(root, text="Real-Time AD User Login Events", font=("Arial", 14, "bold")) header_label.pack(pady=10) log_box = Text(root, wrap="word", font=("Consolas", 10)) scrollbar = Scrollbar(root, command=log_box.yview) log_box.configure(yscrollcommand=scrollbar.set) log_box.pack(side="left", fill="both", expand=True, padx=10, pady=10) scrollbar.pack(side="right", fill="y") # Start monitoring in a background thread monitor_thread = threading.Thread(target=monitor_login_events) monitor_thread.daemon = True monitor_thread.start() root.mainloop()
Bonus:
You can package this script into a standalone EXE using pyinstaller so you don’t need Python installed on the monitor machine:
pyinstaller --onefile --windowed login_monitor.py
Key Notes for All Solutions:
- Permissions: Ensure the running account has read access to the domain's Security logs (domain admin or a dedicated monitoring account works best).
- Filtering: Adjust the event IDs/logon types to match your needs (e.g., exclude service accounts or specific login methods).
- Persistence: For 24/7 monitoring, add the script/EXE to Windows Task Scheduler to run on startup.
内容的提问来源于stack exchange,提问作者NickCarlt

