"“Welke audit trail programma adviseren jullie om RDP sessies te monitoren”"
Dit is gewoon standaard functionaliteit in Windows.
--
Instructions
1. Log in to your PC server with an administrator account.
2. Open the Start menu, go into the "Administrative Tools" section and click "Local Security Policy."
3. Expand the "Local Policies" folder and highlight "Audit Policy."
4. Double-click the item labeled "Audit logon events."
5. Go to the "Local Security Setting" tab at the top of the window.
6. Check the boxes next to "Success" and "Failure."
7. Press the "OK" button to save the settings. Now all Remote Desktop connections will be logged and can be accessed through the Event Viewer.
--
Voor een gratis log analysis pakket, wat lijkt op Splunk, zie bijvoorbeeld Kibana/LogStash -
Kibana http://www.elasticsearch.org/overview/kibana/
LogStash http://www.elasticsearch.org/overview/logstash/