Challenge your skills: Search all logs for applications requesting kerberos tickets

j_k
New Contributor

Common problem: a user is getting locked out of Active Directory "mysteriously"

The challenge: a way to grep or find through the whole computer's log files to figure out whats been making requests recently.

so far I haven't been able to pull it off. something like

sudo grep -r -i kerb .

doesn't yield much. I think this is a universal challenge IT support faces and admins avoid. I assume there isn't a tool to help yet because no one is smart enough to make one, but hey, maybe one of us could?

3 REPLIES 3

bentoms
Release Candidate Programs Tester

@j/k Are they on Sierra? Do they have iCloud enabled?

j_k
New Contributor

@bentoms yes to both

a_stonham
Contributor II

Sounds like the sierra failed auth problem:
https://www.jamf.com/jamf-nation/discussions/21320/sierra-ad-account-lockout-when-setting-up-icloud