AD Auditing with raw edition

Thank you for your replies.

I got the event console working. The rules for auto-close some event IDs are working properly. But the event IDs I want to monitor aren’t going to work. I can’t see anything in the event console when an user account was changed for example. The corresponding event ID 4738 isn’t visible in event console. In event viewer on the domain controller I can see the entry, but not on checkmk.

In the check_mk.user-file my entry looks like this:

- 'Security': all nocontext

That should be fine in my opionion. The connection to the agent is also working properly.

I keep the power shell script in mind. I think the better way of understanding checkmk is to use the out-of-the-box tools.