OpsMgr 2007: How to get alerts for domain group membership changes

imageUsing System Center Operations Manager 2007, you want to get an alert for any change in the domain admin group or any other group for that matter.  If this is something you think you might want to configure then  here are the steps to set this up:

Note: Before we continue – let me stress that using event parameters is the correct way to match on specific lines in an event description wherever possible.  If we try and search the entire event description there is a substantial cost to doing this, from an agent design/performance perspective, as matching on parameter is the lowest impact.  If you match on an event description – this description is localized text and won’t work in all locales.  By writing a rule that matches on event description, if you didn’t specify several other criteria, there is a risk that every single event description would be searched, across all agents.  Very bad.  So keep this in mind if you decide to use this.

1. Domain controller normally generates Event IDs like 632 if Member is added to the group and 633 if member is removed from the group.

2. Domain controller should be working SCOM 2007 Agent.

3. In SCOM Console, go to Authoring, Under Management Pack Objects, click on Rules.

4. From View Menu in console select Scope and then from the list select check box only for ‘Windows Domain Controller’ and click OK.

5. Now right click on ‘Type: Windows Domain Controller’ and select ‘Create a new rule’.

6. Select ‘Alert Generating Rules – Event Based – NT Event Log (Alert)’ under Type of rule to create, and select your choice of destination Management Pack, click Next.

7. Give Rule name of your choice, and give description if required, select Rule Category as ‘Alert’ from drop down, and verify that Rule target is shown as Windows Domain Controller, make sure check box for ‘Rule is enabled’ is selected, click Next.

8. Select Log name as Security, click Next.

9. In the Build the expression, choose options as below:

a. Delete current list by clicking Delete button twice.
b. Click on Insert AND group.
c. Under Parameter name click on button with 3 dots, then select Use parameter name not specified above radio button and type ‘Event Description’ and click OK.
d. Under Operator select ‘Matches regular expression’ from drop down list.
e. In the Value field type ‘Domain Admins’ and hit the Tab key twice so your selection will shift to Insert button.
f. Now click on Insert button and select Insert OR group.
g. Under Parameter name click on button with 3 dots, then select Event ID from drop down under Select from a list of common event properties and click OK.
h. Under Operator select ‘Equals’ from drop down list.
i. Under Value type 632, and hit the Tab key twice so your selection will shift to Insert button.
j. Now click on Insert button and select Insert Expression.
k. Under Parameter name click on button with 3 dots, then select Event ID from drop down under Select from a list of common event properties and click OK.
l. Under Operator select ‘Equals’ from drop down list.
m. Under Value type 633, and hit the Tab key twice so your selection will shift to Insert button.

10. Now click on Next.

11. Give name to Alert of your choice and configure other parameters of alert of your choice.

12. Click on Create button.

This will create the rule and start sending alerts ONLY when members are added or removed only from Domain Admins group.

If you want to get alerts for any domain group, you can remove expression where we specified Domain Admins group in step 9c,9d,9e and have only expressions for EventID 632 and 633.

Related links:

Milan Jajal

Comments (3)

  1. Anonymous says:

    Two things i have noticed while trying to set this up..

    Step 9c – EventDescription should not have a space between event and description, or the rule doesn’t work for me.

    Secondly, i cannot get the alert to display data in the alert description field.  When i add $Data/EventDescription$ (or any other attibute)in the Alert properites tab, the resulting alert displays {0} instead of the event description.  If you go to the alert generated and look at the Alert context tab, the event description is listed here correctly so i know the data is being sent back.  It just wont display it.  

    The reason i want to display the data here is so the email alerts will have more useful data (who changed the group, etc).  

    Is this description being suppressed because it is from the security log?

  2. YoMama says:

    Dear ,OpsMgrNoob

    You are gay.

  3. show box says:

    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?
    For more info on showbox please refer below sites:
    Latest version of Showbox App download for all android smart phones and tablets.
    http://movieboxappdownloads.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.
    For showbox on iOS (iPhone/iPad), please read below articles:
    Showbox for PC articles:
    There are countless for PC clients as it is essentially easy to understand, simple to introduce, gives continuous administration, effectively reasonable. it is accessible at completely free of expense i.e., there will be no establishment charges and after establishment
    it doesn’t charge cash for watching films and recordings.
    http://www.showboxforipad.org/showbox-apk/ Not simply watching, it likewise offers alternative to download recordings and motion pictures. The accompanying are the strides that are to be taken after to introduce Showbox application on Android. The above
    all else thing to be done is, go to the Security Settings on your Android telephone, Scroll down and tap on ‘Obscure sources’.
    Movie Box, an esteemed movies application in which you can find stacks of programs and films. The guide is given here to download Movie Box app to Android and to Apple iOS 9.0.2, iOS 8.4/8.3 and also for the lower versions without Jailbreak.
    Please do login to Showbox application with the help of Ymail. You can login in Ymail from here –
    Sign Up & Do registration for latest movies on Showbox application