<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iLo Active Directory Authentication and event logs in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-active-directory-authentication-and-event-logs/m-p/4733194#M5571</link>
    <description>Hi There,&lt;BR /&gt;&lt;BR /&gt;I guess, You are looking for directory-enabled remote management. You can use HP schema directory integration with ILO to achieve this.&lt;BR /&gt;&lt;BR /&gt;please refer ILO 2 userguide&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00553302/c00553302.pdf" target="_blank"&gt;http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00553302/c00553302.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;Aftab&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 04 Jan 2011 03:00:59 GMT</pubDate>
    <dc:creator>Ali</dc:creator>
    <dc:date>2011-01-04T03:00:59Z</dc:date>
    <item>
      <title>iLo Active Directory Authentication and event logs</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-active-directory-authentication-and-event-logs/m-p/4733193#M5570</link>
      <description>I was wondering if anyone can confirm my observations or can report actual success in what I am trying to accomplish.&lt;BR /&gt;&lt;BR /&gt;I am using a Security Incident and Event Monitor application an am trying to capture the events of either succesfully or unsucessfully logging into iLo.  My goal would be to detect an attack, perhaps even detect an an authorized account login at an inappropriate time, or have the event for forensics later on.&lt;BR /&gt;&lt;BR /&gt;It is my first round conclusion that Active Directory is not recording the source of the authentication, ie, it can't tell one iLo from another iLo.   &lt;BR /&gt;&lt;BR /&gt;Using the Dell equivalent, DRAC, has been easy, since it can output events in syslog.   I don't have any iLo, but my understanding is that it has SNMP, which I dread trying to configure on my SIEM side.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2011 22:04:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-active-directory-authentication-and-event-logs/m-p/4733193#M5570</guid>
      <dc:creator>Al W.</dc:creator>
      <dc:date>2011-01-03T22:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: iLo Active Directory Authentication and event logs</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-active-directory-authentication-and-event-logs/m-p/4733194#M5571</link>
      <description>Hi There,&lt;BR /&gt;&lt;BR /&gt;I guess, You are looking for directory-enabled remote management. You can use HP schema directory integration with ILO to achieve this.&lt;BR /&gt;&lt;BR /&gt;please refer ILO 2 userguide&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00553302/c00553302.pdf" target="_blank"&gt;http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00553302/c00553302.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;Aftab&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Jan 2011 03:00:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-active-directory-authentication-and-event-logs/m-p/4733194#M5571</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2011-01-04T03:00:59Z</dc:date>
    </item>
  </channel>
</rss>

