# Detecting Active Directory Activity

**URL:** <https://discuss.elastic.co/t/detecting-active-directory-activity/363477>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 20, 2024, 2:58pm UTC](https://discuss.elastic.co/t/detecting-active-directory-activity/363477 "2024-07-20T14:58:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oolong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oolong/32/136182_2.png) [@Oolong](https://discuss.elastic.co/u/Oolong)\
**Post date:** [July 20, 2024, 2:58pm UTC](https://discuss.elastic.co/t/detecting-active-directory-activity/363477/1 "2024-07-20T14:58:58Z")

</div>

Hi Everyone,

Is it possible to detect active directory activity with winlogbeat ?  
i.e. - A new user getting created  
- A user being deleted  
- Password resets

If yes, can someone point me to documentation that i can follow.

---

<div class="post-metadata">

**Author:** ![Oolong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oolong/32/136182_2.png) [@Oolong](https://discuss.elastic.co/u/Oolong)\
**Post date:** [July 20, 2024, 3:24pm UTC](https://discuss.elastic.co/t/detecting-active-directory-activity/363477/2 "2024-07-20T15:24:06Z")

</div>

Removed #dashboard, #elastic-stack-alerting

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 20, 2024, 6:50pm UTC](https://discuss.elastic.co/t/detecting-active-directory-activity/363477/3 "2024-07-20T18:50:27Z")

</div>

Winlogbeat doesn't detect activity per se. It reads the events that are already being reported to the Windows event log and then sends them to Elasticsearch.

So yes, if your Security event log contains events reported by Active Directory then Winlogbeat will capture them and write them to Elasticsearch.

When a user is deleted then [Event ID 4726](https://windows-event-explorer.app.elstc.co/publisher/Microsoft-Windows-Security-Auditing/event/4726/v0) will be logged to the `Security` channel. And similarly when a password is reset [Event ID 4724](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4724) is logged.

If you install [Elastic Agent](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) it will send the logs from the Security channel to Elasticsearch by default. That data can be used with the [SIEM](https://www.elastic.co/security/siem).

---

<div class="post-metadata">

**Author:** ![Oolong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oolong/32/136182_2.png) [@Oolong](https://discuss.elastic.co/u/Oolong)\
**Post date:** [July 20, 2024, 8:12pm UTC](https://discuss.elastic.co/t/detecting-active-directory-activity/363477/4 "2024-07-20T20:12:19Z")

</div>

Thank you, i can see the events.
