RDPSoft

Remote Desktop and Terminal Server Software

We Make RDS, XenApp & VDI Monitoring/Reporting Easy and Affordable
  • Products / Services
    • Not Sure Where To Start?
    • The Complete Monitoring and Management Bundle For RDS and AVD
    • RDS / AVD Monitoring & Reporting
      • Remote Desktop Commander Suite
    • RDS / AVD Management and RMM Tools
      • Remote Desktop Commander Lite (Free RDS/AVD Management Tool)
      • Remote Assistance RMM Tool + Delegation of Management for RDS/AVD Support Desk
    • RDS Synthetic Login Monitoring / Connection Time / Uptime Monitoring Tools
      • Remote Desktop Canary
    • Consulting and Professional Services
      • RDS Performance Audit
      • Custom Report Design Services
      • Training and Other Professional Services
  • Download
    • Lite: Free RDS/Citrix Session and Farm Manager
    • Lite With Premium Management Features
    • Suite: Installer and Release Notes
    • Remote Desktop Canary – Request a Demo/Trial
    • Request Upgrade To New Version
  • Buy
    • The Complete RDS/AVD Monitoring and Management Bundle Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Commander Suite Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
      • Buy Perpetual License(s)
    • Premium Management Features Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Canary Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Buy Incident Based Support Packages
    • Pricing
  • Blog
  • Support
    • Contact Support / Submit Ticket
    • RDPSoft Knowledge Base
  • Contact
  • Partners

5 Key Synthetic Login Monitoring Features Available In Remote Desktop Canary v2.0+

March 4, 2020 By admin Leave a Comment

We get so much great feedback from our customers, and as any software solution matures, it’s easy to lose track of the details of features and the reasons customers need them.

In the case of our Remote Desktop Canary, some key features in v2.0+ have made it the synthetic login monitoring workhorse that it is.

[Read more…]

Filed Under: Remote Desktop Security, Software Releases, Synthetic RDP Tagged With: rdp application performance monitoring, rdp synthetic login test, rdp uptime, rds synthetic login test, remote desktop login time, remote desktop monitoring, remote desktop synthetic login, slow rdp login, slow rdp login script

RDS Logins & Logon Failure Tracking (And More) in Remote Desktop Commander v4.5+

September 27, 2018 By admin Leave a Comment

Though later versions of our Remote Desktop Commander Suite build on these key features, it’s worth drilling into these specific capabilities in RDS logins and logon failure tracking (plus some extra stuff we’re sure will interest you) that were introduced starting with v4.5:

Consolidate All RDS Logins and Logon Failures, Regardless Whether Or Not They Occurred On Session Hosts Or Remote Desktop Gateway Servers

Our CEO, Andy Milford, has written at length about the challenges faced when attempting to correlate RDP logon failure data from session hosts at his PureRDS.org blog. Attempting to track successful RDP logins is no picnic either, as multiple log files from multiple different systems – the session host servers and remote desktop gateway servers – must be consulted and the information correlated.

In version 4.5 of the Remote Desktop Commander Suite, the Remote Desktop Reporter Service automatically collects and correlates key events from event log files on Session Host servers and Remote Desktop Gateway servers. The result is a treasure trove of valuable login and logon failure data that it retains in its SQL database, allowing us to deliver the incredible new features described below.

Geolocate RDS Logins and Logon Failures In the User IP Geolocation Dashboard – Find Out Where Your Users Are Working From, and Locate the Source Of Brute Force RDP Hack Attempts

Geolocate RDP Logon Failures
Perform deep analysis of RDP logon failures and user logins using the User IP Geolocation Dashboard.

Remote Desktop Services login and logon failure data correlation from session hosts and gateways is a valuable feature in its own right, but the rich visualizations of this data is what sets Remote Desktop Commander Version 4.5+ apart from the competition. The User IP Geolocation Dashboard combines IP geolocation data with interactive worldwide maps and tabular, filterable tables so administrators can zero in on both legitimate RDS users and hackers.

Locate The Source of RDP Brute Force Hack Attempts
Filter RDP logon failure and login data by username, time frame, computer, and sort the data by username, region, country etc.

Our dashboard is completely extensible via PowerShell scripts, which are designed to receive selected server names, usernames, and IP addresses as input parameters. This is especially useful for the remediation of inbound hack attempts.

Remediate Brute Force RDP Attacks
Extend the capabilities of the dashboard with PowerShell

Instantly build reports from the filtered RDP login and logon failure data in the dashboard, or simply export the data to comma-delimited text.

Report on RDP Logon Failures
Export RDP login data and generate reports in PDF, Word, or Excel.

Schedule Daily User Login and Logon Failure Reports

RDP Logon Failure Reports
Build RDP login reports manually, or schedule them to run daily to gain insight on where users are connecting from.

Scheduled reports make it easy to keep track of both where your users are routinely connecting from, as well as the sources of hacking and penetration attempts. Group login and logon failure data by country or by user. With routine review of these reports, you can quickly spot geographic RDP login anomalies that could be suggestive of a compromised user account.

See The Actual IP Address and Geolocation Information for User Sessions In Existing Time Tracking Reports.

By default, the Microsoft Terminal Services client (MSTSC) does not report its actual global IP address when connecting to a terminal server. When connecting through a Remote Desktop Gateway system, no IP address information is transmitted at all. Many admins have requested that we transform the incorrect or missing IP address information with the actual global IP address of the user, whether or not they are connecting through a RD Gateway.

Based on this feedback, we have retrofitted several existing reports, such as the User Sessions – Session Details By User report family, to include the correct global IP of the user based on the correlated log data now collected by our central polling service. Also, when possible, the global IP address is accompanied with the geographic region of the user’s ISP

Remote Desktop User Time Tracking Report
Many existing user activity reports now include the resolved, Global IP of the user, and ISP geolocation information when available.

Massively Reduce Database Storage Requirements With Performance Threshold Database Pruning

As you can see, we’ve mainly talked about logins and logon failures so far, and we’re talking about lots of data that we work with. So, we have to be ready to handle it all. Which brings us to a related feature.

Collecting in-depth performance data on a per-user and per-program basis with our agent service is great, but it’s easy to generate a lot of data in SQL by doing so. Version 4.5+ has a nifty new feature that we call “Performance Threshold Database Pruning.”

Now, in addition to purging out agent-based performance data based on date, you can elect to keep only the agent data associated with times of high load on session host servers. You can define what you consider to be high load both in terms of CPU usage or memory utilization, or a combination of both. Using this new feature can drastically reduce the amount of data stored in SQL over time, in many cases by over 80%.

Control RDS Performance Database Growth
Using Performance Threshold Database Tuning, tightly control the size of your SQL database growth.

. . . And What’s The Latest?

Of course, features change and mature, so be sure to find out the latest developments with our Remote Desktop Commander Suite by requesting a web demo with an RDPSoft solutions expert.

Updated: November 2020.

Filed Under: RDP Login Tracking, RDP Logon Failure Tracking, RDP Security, Remote Desktop Security, Software Releases Tagged With: geolocating RDP logins, rdp hack attempt, rdp login, rdp logon failure, RDP Security, RDS Security

  • Email
  • Google+
  • LinkedIn
  • Twitter
  • YouTube

Not Sure Where To Start?

In just a few moments, you can find the right fit of solutions and even services for your needs.

> Get Going Now.

Help Documents

Remote Desktop Commander
Help and Users Guide
Release Notes (ver 6.x)

Sign Up for Remote Desktop Tips and RDPSoft Updates

Blog Topic Categories

  • Azure RemoteApp
  • Azure Virtual Desktop
  • citrix edgesight
  • Citrix Edgesight Replacement
  • Citrix Shadowing
  • Cloud RDP Monitoring
  • Performance
  • RDP Disconnects
  • RDP Latency
  • RDP Login Time
  • RDP Login Tracking
  • RDP Logon Failure Tracking
  • RDP Logs
  • RDP Loss Rate
  • RDP Security
  • RDP Transmission Rate
  • RDS Infrastructure
  • RDS License Metering
  • RDS Licensing
  • Remote Desktop Bandwidth
  • Remote Desktop CPU
  • Remote Desktop Management
  • Remote Desktop Memory
  • Remote Desktop Memory Usage
  • Remote Desktop Monitoring
  • Remote Desktop Performance
  • Remote Desktop Protocol
  • Remote Desktop Reporting
  • Remote Desktop Security
  • Remote Desktop Services
  • Remote Desktop Services Free Tools
  • Remote Desktop Services Hotfix
  • Sensitive Data
  • Server 2012 TSAdmin Replacement
  • Shadow User
  • Software Releases
  • SPLA Reporting
  • Synthetic RDP
  • Telecommuting/Teleworking
  • Terminal Server Logging
  • Terminal Server Monitoring
  • Uncategorized
  • User Activity Monitoring
  • User Productivity
  • Windows 2008 Terminal Server
  • Windows Virtual Desktop
  • WVD Login Time
  • XenApp Monitoring
  • XenApp Reporting

Recent Posts

  • Remote Desktop Commander v6.5 Now Available!
  • AVD Monitoring: An Easy Step-By-Step Approach
  • Three Reasons Why You Need to Monitor CAP and RAP Failures On Your Remote Desktop Gateways
  • Remote Desktop Commander v6.0+ Highlights
  • Connection Broker Monitoring

From the RDPSoft Blog

  • Remote Desktop Commander v6.5 Now Available!
  • AVD Monitoring: An Easy Step-By-Step Approach
  • Three Reasons Why You Need to Monitor CAP and RAP Failures On Your Remote Desktop Gateways
  • Remote Desktop Commander v6.0+ Highlights
  • Connection Broker Monitoring
  • Email
  • Google+
  • LinkedIn
  • Twitter
  • YouTube

We Do “Single Pane of Glass” Monitoring and Management for RDS

Top Level Deployment Dashboard

One of the biggest criticisms leveled against Microsoft's Remote Desktop Services as an end user computing (EUC) platform is its complete lack of integrated management and monitoring tools. … Learn more about our centralized RDS monitoring and management >

Reach Out

For fastest response, reach out via our sales and support contact forms.

Sales
US: 1-855-738-8457 x1
Outside the US: 1-702-749-4325 x1

Support
for Evaluators and Priority Support Customers
US: 1-855-738-8457 x2
Outside the US: 1-702-749-4325 x2

Copyright © 2013 - 2020 RDPSoft. All rights reserved. · RDPSoft is the sole authorized publisher and distributor of the following software titles: Remote Desktop Commander, Premium Management Features, Remote Desktop Canary · Sitemap