Ondřej Ševeček | GOPAS a.s. MCSM:Directory Services | MVP:Enteprise Security | CISA | CEH | CHFI | facebook: ondrej.sevecek.official.

Slides:



Advertisements
Similar presentations
IP ADDRESS MANAGEMENT [IPAM]
Advertisements

Dan Stolts Chief Technology Strategist Microsoft Corporation Blog: Managing and Monitoring Critical Infrastructure.
File Server Organization and Best Practices IT Partners June, 02, 2010.
System Center Operations Manager 2007 Management Pack Roadmap (Apr/May 2008)
Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | CEH | | |
What to expect.  Linux  Windows Server (2008 or 2012)
Module 10: Troubleshooting AD DS, DNS, and Replication Issues.
2.1 Installing the DNS Server Role Overview of the Domain Name System Role Overview of the DNS Namespace DNS Improvements for Windows Server 2008 Considerations.
Windows Monitoring Yancy Ribbens
Chapter 7 HARDENING SERVERS.
Hands-On Microsoft Windows Server 2003 Networking Chapter 6 Domain Name System.
Hands-On Microsoft Windows Server 2003 Administration Chapter 9 Administering DNS.
Microsoft Windows Domains Structure and Services Chatziioannidis Christos Computer & Informatics Engineer Computer & Networking Services Computer Technology.
1  Teacher : KIM Bunthoeurn  Group 3  Group members: o ENG Phally o CHHENG Sounly o POV Sopheap o SRORNG Voleak o NGET Phanny  Topic: Company description.
Pro Exchange SPAM Filter An Exchange 2000 based spam filtering solution.
Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint | Smart card.
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
1 Enabling Secure Internet Access with ISA Server.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
MP Author MP Visual Studio Authoring Extensions (VSAE)
Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | | |
Event Viewer Was of getting to event viewer Go to –Start –Control Panel, –Administrative Tools –Event Viewer Go to –Start.
Group Policy in Microsoft Windows Active Directory.
Chapter 7 WORKING WITH GROUPS.
Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | Certified Ethical Hacker | |
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Module 1: Introduction to Administering Accounts and Resources
SOE and Application Delivery Gwenael Moreau, Abbotsleigh.
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
Windows Server 2008 R2 Domain Name System Chapter 5.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Module 9: Active Directory Domain Services. Overview Describe new features in AD DS List manageability and reliability enhancements in AD DS.
Bezpečnost Windows pro pokročilé: uživatelské účty GOPAS: | | Ing. Ondřej Ševeček | GOPAS a.s. |
Free, online, technical courses Take a free online course. Microsoft Virtual Academy.
Module 2: Installing and Maintaining ISA Server. Overview Installing ISA Server 2004 Choosing ISA Server Clients Installing and Configuring Firewall Clients.
Module 9: Fundamentals of Securing Network Communication.
Bezpečnost Windows pro pokročilé: přístup do sítě GOPAS: | | Ing. Ondřej Ševeček | GOPAS a.s. | MCM:Directory.
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
Module 7 : Configuration I Jong S. Bok
Chris Almida Sr. Program Manager Microsoft Corporation SESSION CODE: WSV206.
Designing Secure SharePoint External Access Ondrej Sevecek | MCM: Directory | MVP: Security |
Bezpečnost Windows pro pokročilé: zajímavosti a UAC GOPAS: | | Ing. Ondřej Ševeček | GOPAS a.s. |
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint | Event Filtering.
Microsoft Management Seminar Series SMS 2003 Change Management.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Managing and Monitoring the Microsoft Application Platform Damir Bersinic Ruth Morton IT Pro Advisor Microsoft Canada
Chapter 4- Part3. 2 Implementing User Profiles A local user profile is automatically created at the local computer when you log on with an account for.
Agenda - SCOM 2007 R2 Management Packs Operations Manager Console Console Demonstration.
Introduction to Active Directory
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
MICROSOFT TESTS /291/293 Fairfax County Adult Education Courses 1477/1478/1479.
Bezpečnost Windows pro pokročilé: protokoly a sledování přihlášení GOPAS: | | Ing. Ondřej Ševeček.
Module 14: Advanced Topics and Troubleshooting. Microsoft ® Windows ® Small Business Server (SBS) 2008 Management Console (Advanced Mode) Managing Windows.
BÄTTRE UTBILDNINGSRESULTAT. NÅ HÖGRE MED KUNSKAP.
Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint | Passwords.
Ondrej Sevecek | GOPAS a.s. MCSM:Directory Services | MVP:Enteprise Security | CISA | CEH | CHFI | facebook: ondrej.sevecek.official.
Ondrej Sevecek | GOPAS a.s. MCSM:Directory Services | MVP:Enteprise Security | CISA | CEH | CHFI | Enterprise certification.
Pass Microsoft Installing and Configuring Windows Server 2012 exam in just 24 HOURS! 100% REAL EXAM QUESTIONS ANSWERS Microsoft Installing.
Microsoft Exam
Module 3: Enabling Access to Internet Resources
100% Exam Passing Guarantee & Money Back Assurance
TechEd /14/2018 8:19 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
SharePoint and IIS core integration
Configuration Of A Pull Network.
Designing IIS Security (IIS – Internet Information Service)
SharePoint Server Assessment Results
GOPAS TechEd 2012 Kerberos Delegation
Presentation transcript:

Ondřej Ševeček | GOPAS a.s. MCSM:Directory Services | MVP:Enteprise Security | CISA | CEH | CHFI | facebook: ondrej.sevecek.official | SCOM event queries how the object model works GOLD PARTNER:Hlavní odborný partner:

Infrastructure recap  SCOM management server  SCOM agent (health service) –Operations Manager event log new configuration became active new MP downloaded

Management pack  XML configuration plus scripts .XML,.MP file or.MPB bundle file  Sealed (digitally signed) or un-sealed and modifiable –different MP cannot target/reference objects from an unsealed MP –cannot define classes  Strict versioning –can update any management pack with newer version –dependent MPs should work –cannot remove MP which other MPs depend on  Downloaded to clients –%programfiles%\Microsoft Monitoring Agent\Agent\Health Service State\Management Packs

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.DNS Microsoft Windows Server DNS Monitoring

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.DNS Microsoft Windows Server DNS Monitoring Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.DNS Microsoft Windows Server DNS Monitoring Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.DNS Microsoft Windows Server DNS Monitoring Sevecek.Overrides Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery

Better to separate overriding MPs Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.DNS Microsoft Windows Server DNS Monitoring Sevecek.Overrides.AD Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery Sevecek.Overrides.DNS

base/abstract class inherited object class object class Management pack elements Disco Object instance object instance Object instance object instance singleton monitor rule monitor

object class Object instance object class Object instance object class Object instance Concept of targeting Disco object class Object instance object instance Agent Disco object class Object instance monitor rule

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery ReadOnlyDC.Computer DFSR Domain Forest Site DomainControllerRole

Management pack dependencies Microsoft.Windows.Library Windows Core Library Microsoft.Windows.Server.AD.Library Active Directory Server Common Library Microsoft.Windows.Server.AD.2008.Discovery Active Directory Server 2008 and above Discovery Microsoft.Windows.Server.AD.2000.Discovery Active Directory Server 2000 Discovery Microsoft.Windows.Server.AD.2003.Discovery Active Directory Server 2003 Discovery ReadOnlyDC.Computer DFSR Domain Forest Site DomainControllerRole Microsoft.Windows.Server. AD.2008.Monitoring Active Directory Server 2008 and above Monitoring

delete logs start web application SQL instance Manufacturing Module – Monitor – Action principle ok warning critical process punning and CPU < 80% Web instance SharePoint Web instance HRAgenda Web instance Manufacturing service name process ID CPU < 80% CPU > 80% stop mail restart service

SQL instance Manufacturing Module – Rule – Action principle event log user account locked Web instance SharePoint Web instance HRAgenda Web instance Manufacturing service name process ID mail to admin sms to user

Sample environment gopas.virtual (GPS) sevecek.com (SEVECEK) mutual forest non-selective SCOM 2012 R2

Sample environment DC R2 DC R2 SEVECEK-DC 2012 R2 RR 2003 gopas.virtual _msdcs.gopas.virtual gopas.cz sevecek.com gopas.cz inet Client81 8.1

Sample environment DC R2 DC R2 SEVECEK-DC 2012 R2 RR 2003 gopas.virtual _msdcs.gopas.virtual gopas.cz sevecek.com gopas.cz sevecek.com gopas.virtual Client81 8.1

Sample environment DC R2 DC R2 SEVECEK-DC 2012 R2 RR 2003 gopas.virtual _msdcs.gopas.virtual gopas.cz sevecek.com gopas.cz sevecek.com gopas.virtual _msdcs.gopas.virtual gopas.cz Client81 8.1

Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Zone Windows DNS Zone DNS relationship basics Microsoft.Windows.Computer Windows Computer Microsoft.Windows.Server.DNS.Server Windows DNS Server Microsoft.Windows.Server.DNS.Zone Windows DNS Zone hosting

Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Forwarder Windows DNS Forwarder DNS relationships Microsoft.Windows.Computer Windows Computer Microsoft.Windows.Server.DNS.Server Windows DNS Server Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Forwarder Windows DNS Forwarder hosting Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address hosting

Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Forwarder Windows DNS Forwarder DNS relationships Microsoft.Windows.Computer Windows Computer Microsoft.Windows.Server.DNS.Server Windows DNS Server Microsoft.Windows.Server.DNS.Zone Windows DNS Zone Microsoft.Windows.Server.DNS.Forwarder Windows DNS Forwarder hosting Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address Microsoft.Windows.Server.DNS.Forwarder.IPAddress. Unconditional / Conditional.Forward / Conditional.Reverse Windows DNS Forwarder IP Address Unconditional / Conditional Forward / Conditional Reverse Microsoft.Windows.Server.DNS.Forwarder.IPAddress Windows DNS Forwarder IP Address hosting

Microsoft.Windows.Server.DNS.Server.2008R2.Group DNS 2008 R2 Servers Windows DNS Zone DNS relationships DNS Forwarder Microsoft.Windows.Server.DNSDomain Windows DNS Domain hosting Windows Computer Forwarder IP Address hosting Windows DNS Server Windows DNS Zone Forwarder IP Address Windows DNS Zone containment Windows Computer Windows DNS Server containment

Windows DNS Zone Unit monitors DNS Forwarder DNS Domain hosting Windows Computer Forwarder IP Address hosting Windows DNS Server Windows DNS Zone Forwarder IP Address Forwarder IP Address Windows DNS Zone containment Windows Computer Windows DNS Server

XML XPath queries EventData/*[name()='Data' *[name()='EventData]/*[name()='Data' EventData/DataItem/*[name()='EventData']/*[name=()='Data' or you can use a shorter form //*[name()='EventData']/*[name=()='Data'

Děkuji za pozornost! GOC170 - SCOM authoring Ondřej Ševeček | GOPAS a.s. MCSM:Directory Services | MVP:Enteprise Security | CISA | CEH | CHFI | facebook: ondrej.sevecek.official |

Aktuální a navazující kurzy sledujte na DÁREK PRO VÁS! TechEd-DevCon 2016! …získejte tričko TechEd-DevCon 2016!Vyplňte dotazníkové hodnocení a… TechEd party! Xbowling Strašnice, Buďte The Best IT Pro nebo The Best Developer SOUTĚŽ! SOUTĚŽ! SOUTĚŽ!