Windows - NTDS - Auths (WMI)
|host_description| - NTDS - Auths
1
120
750
on
on
2
on
on
100
0
1000
Auths Per Sec
hash_080019eab6dbee49011c47a2f132de605ec21d
FF0000
FF
4
1
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Kerberos Auths:
5
hash_080019eab6dbee49011c47a2f132de605ec21d
0
FF
9
4
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Current:
6
hash_080019eab6dbee49011c47a2f132de605ec21d
0
FF
9
1
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Average:
7
hash_080019eab6dbee49011c47a2f132de605ec21d
0
FF
9
3
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Maximum:
on
8
hash_08001905faecbe907ab2633fe694a750f0e9e6
4444FF
FF
4
1
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
NTLM Auths:
9
hash_08001905faecbe907ab2633fe694a750f0e9e6
0
FF
9
4
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Current:
10
hash_08001905faecbe907ab2633fe694a750f0e9e6
0
FF
9
1
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Average:
11
hash_08001905faecbe907ab2633fe694a750f0e9e6
0
FF
9
3
0
hash_060019e9c43831e54eca8069317a2ce8c6f751
Maximum:
on
12
Data Source [NTLMAuths]
task_item_id
hash_00001942ee1eac7d42cc0675bc6bc32056ce0a|hash_000019fc7b4e759bfca27973814c382120ab62|hash_000019435b5f64151f980a6be8810cbd677954|hash_00001902d5afff15ab95f2301e3abcb97db6dd
Data Source [KerberosAuths]
task_item_id
hash_00001991e69fe0470bd740707d6600ab6c3397|hash_0000197f83ed18442c3992315b6ecc11848746|hash_000019ef04d702398184d6271991872d2191b4|hash_000019228cc080906d291fd8d108975f3bf3f3
Windows - NTDS - DS (WMI)
|host_description| - NTDS - DS
hash_030019e8ad067611631abf48be5adaabeb6d91
300
on
hash_150019c21df5178e5c955013591239eb0afd46|hash_1500190d9c0af8b8acdc7807943937b3208e29|hash_1500196fc2d038fb42950138b0ce3e9874cc60|hash_150019e36f3adb9f152adfa5dc50fd2b23337e|hash_150019283ea2bf1634d92ce081ec82a634f513
Binds
0
500000
2
600
hash_0700194afd93c517a623d27b073aef36af239f
NameTranslations
0
500000
2
600
hash_0700190e4c8cd0a3c1c0a514795df1df6646f9
Reads
0
500000
2
600
hash_07001931bedde7ad11dcef9a80549f4235a408
Searches
0
500000
2
600
hash_070019325418f7062efb2246f9c59fdcecb180
Writes
0
500000
2
600
hash_070019e8a332821bf54e50615da5f0889809f3
KerberosAuths
0
500000
2
600
hash_070019d14fa9d86687447d66feaed62e4c04ad
NTLMAuths
0
500000
2
600
hash_07001939c1cacfb7e24eb8b3df033503939963
hash_070019549cd359e65c98a63b6ccc93d6777ac7
hash_070019e1be275015382807006fcc5f0a334d0f
hash_07001917604fa0bde1479a81d5e343a8365124
hash_07001935f8275412491d899fbb6694c2fe9fbe
on
/etc/cacti/cactiwmi.pw
hash_070019ac03e736b666de5cc9f57be8cfc5f08c
Win32_PerfRawData_NTDS_NTDS
hash_07001930bfcd5c65edaaeced18df3da45ed35f
DSClientBindsPersec,DSClientNameTranslationsPersec,DSDirectoryReadsPersec,DSDirectorySearchesPersec,DSDirectoryWritesPersec,KerberosAuthentications,NTLMAuthentications
hash_070019c0fde84802c8917276c75f12dc0e775a
WMI - NTDS (DS)
1
/usr/bin/php -q <path_cacti>/scripts/wmi.php -h '<host>' -u '<credential>' -w '<class>' -n '<namespace>' -k '<filter>' -v '<filterval>' -c '<columns>'
Hostname
hostname
in
host
Credential
in
credential
Class
in
class
Columns
in
columns
Filter
on
in
filter
Filter Value
on
in
filterval
DSClientBindsPersec
on
out
DSClientBindsPersec
DSClientNameTranslationsPersec
on
out
DSClientNameTranslationsPersec
DSDirectoryReadsPersec
on
out
DSDirectoryReadsPersec
DSDirectorySearchesPersec
on
out
DSDirectorySearchesPersec
DSDirectoryWritesPersec
on
out
DSDirectoryWritesPersec
NTLMAuthentications
on
out
NTLMAuthentications
KerberosAuthentications
on
out
KerberosAuthentications
Namespace
on
in
namespace
Daily (5 Minute Average)
0.5
1
600
86400
1|3
Weekly (30 Minute Average)
0.5
6
700
604800
1|3
Monthly (2 Hour Average)
0.5
24
775
2678400
1|3
Yearly (1 Day Average)
0.5
288
797
33053184
1|3
Hourly (1 Minute Average)
0.5
1
500
14400
1|3
Normal
%8.2lf %s