Demonstration
In this section, let's go ahead and see how we can use built-in Windows monitoring and audit capabilities. In order to do these configurations, you need to have domain administrator or enterprise administrator privileges.
Reviewing events
Event Viewer can simply be opened by running eventvwr.msc
. The same MMC can also be used to connect to a remote computer using the Connect to Another Computer... option, as highlighted in the following screenshot:
Figure 19.4: Review events on another computer
We can simplify this by creating server groups in Server Manager. Server groups allow us to group systems running similar server roles or acting as part of a distributed system.
Before we go ahead and create server groups, we need to take note of the following information:
- We need an account that has administrator privileges for all the member servers to create and use server groups.
- We must enable Windows Remote Management (WinRM...