# How monitoring eventlog from 2 domains controlers

**URL:** <https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099>\
**Category:** Kibana\
**Created:** [June 17, 2016, 6:57am UTC](https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099 "2016-06-17T06:57:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![santyuste](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@santyuste](https://discuss.elastic.co/u/santyuste)\
**Post date:** [June 17, 2016, 6:57am UTC](https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099/1 "2016-06-17T06:57:54Z")

</div>

Hello,  
I want to monitoring all eventlogs from 2 domains controlores.  
how can monitoring graph this from kibana

Thans

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [June 17, 2016, 4:58pm UTC](https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099/2 "2016-06-17T16:58:53Z")

</div>

I'm not sure I understand your question. Are you already indexing the event logs into Elasticsearch? What exactly are you struggling with?

---

<div class="post-metadata">

**Author:** ![santyuste](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@santyuste](https://discuss.elastic.co/u/santyuste)\
**Post date:** [June 17, 2016, 5:00pm UTC](https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099/3 "2016-06-17T17:00:42Z")

</div>

Hello Lukas

I installed ossec-wazzuh with kibana on linux server  
i want to monitoring winddows eventlog from 2 active directory servers.  
I have configured agent in linux for this servers and install ossec agent in windows server

The configuration agent from windows is  
\<ossec\_config\>  
  
192.168.12.14  
  
\</ossec\_config\>

 Application eventlog Security eventlog System eventlog 

I recibe this log in kibana:

{"rule":{"level":3,"comment":"Windows User Logoff.","sidid":18149,"firedtimes":1,"groups":["windows"],"PCI\_DSS":["10.2.5"]},"dstuser":"Administrador","full\_log":"2016 Jun 07 10:33:48 WinEvtLog: Security: AUDIT\_SUCCESS(551): Security: Administrador: PC-XP: PC-XP: Cierre de sesi\xF3n iniciada por el usuario: Nombre usuario: Administrador Dominio: DOM.local Id. de inicio de sesi\xF3n: (0x0,0xb73d9) ","id":"551","status":"AUDIT\_SUCCESS","data":"Security","systemname":"PC-XP","decoder":{"name":"windows"},"hostname":"agent01","agentip":"any","timestamp":"2016 Jun 07 10:33:51","location":"WinEvtLog"}

Please, how can i do for add daskboard in kibana graphic interface  
for the eventolog monitoring?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:50pm UTC](https://discuss.elastic.co/t/how-monitoring-eventlog-from-2-domains-controlers/53099/4 "2017-07-06T13:50:08Z")

</div>


