BeyondInsight Reporting in AD Bridge

The AD Bridge GPO, User Monitor, sends the following data to the BTEventDBReaper service that then forwards the data to BeyondInsight:

  • Users that are added, deleted, or changed.
  • If the user has the Allow Logon rights GPO set, then changes and deletions are recorded.

No historical data is retained in the BeyondInsight database. Data is overwritten when new updates are sent to the BeyondInsight database.

Requirements

  • Configure a group policy that has user monitor and event forward configured.
  • If running an earlier version of User Monitor, you must upgrade the BTEventDBReaper service before upgrading User Monitor.
  • After BTEventDBReaper is upgraded, you can upgrade the agent. If the BTEventDBReaper service is not updated first, it cannot process the records from the agent which will result in a failure of processing data.
  • Allow Logon Rights must be turned on and configured for users and groups that you want to log into the agents.

If Allow Logon Rights is not configured, the BeyondInsight report will show a single record for All Users. To populate the report with individual users, Allow Logon Rights must be set.

  • AD Bridge collectors must be installed.

For more information, see Set Up the Collection Server.

  • BeyondInsight 6.2 or later.

Generate a Certificate

Generate a client certificate using the BeyondInsight Configuration tool. A certificate must be created and copied to the AD Bridge server certificate store to ensure secure communications.

To generate a certificate:

  1. Run the configuration tool, and then click Certificate Management.
  2. Select Generate Certificate, and then select Client Certificate from the Certificate type menu.
  3. Enter a password.
  4. Click OK.

Copy the Certificate to the AD Bridge Server

To copy the certificate:

Import menu option in the MMC Certificates Snap-in

  1. Log into the AD Bridge server, open MMC and add the Certificates Snap-in for the Local Computer account.
  2. Expand Certificates (Local Computer).
  3. Right-click Trusted Root Certificates > All Tasks, and select Import.
  4. Import the certificates created using the BeyondInsight Configuration tool.

 

  1. Move the client certificate (eEyeCmsClient) to the Personal certificates store.

Run the Reporting Database Connection Manager Tool

You must establish a connection to the BeyondInsight server.

To run the DBUtilities tool:

Reporting Database Connection Manager in the Start menu

  1. From the Start menu, select Reporting Database Connection Manager. You must run the connection manager as Administrator. Right-click the menu item, and then select Run as administrator.
    • Alternatively, you can also run the tool from the command line:
    • bteventdbreaper /gui

 

  1. Check the Enable BeyondInsight box.

Reporting Database Connection screen

  1. Enter the URL to the BeyondInsight server.
  2. Enter the name of the client certificate generated earlier.
  3. Optionally, create a workgroup name. A workgroup name can be used as a unique identifier.
  4. Click Test Connection to ensure the connection between the servers is successfully established.
  5. Click OK.

 

View Reports in BeyondInsight Analytics and Reporting

To view reports:

  1. Log into Analytics & Reporting.
  2. From the menu, select View All Reports.

Log into BeyondInsight Analytics and Reporting

  1. Select AD Bridge.

 

  1. Select a report.

Configure report in BeyondInsight Analytics and Reporting

  1. Enter the report parameters, and then click View Report.