3
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Windows端末の操作ログを標準機能だけでCloudWatch Logsに集める

3
Last updated at Posted at 2026-10-08

はじめに

誰がいつどのサーバへ接続し、端末上で何を実行したかを記録として残したいことがあります。今回は追加のソフトウェアを使わず、AWSの標準機能だけでWindows端末のログを取得する方法を検証しました。

fig01.png

水色が端末側で設定するもの、緑がAWS側のサービスです。

Active Directoryのグループポリシーで監査設定を有効にして、既定では出力されないイベントログを追加で出力させます。端末にCloudWatch Agentを入れて、出力されたイベントログをVPCエンドポイント経由でCloudWatch Logsへ送信する流れです。端末は検証のためAmazon WorkSpacesを使用し、ハイブリッドアクティベーションでSystems Managerに登録しています。EC2以外の端末をSystems Managerの管理対象にする仕組みです。ディレクトリはAWS Managed Microsoft ADを使用しています。

CloudWatch Logsへ送信するイベントログ

Windowsが記録しているイベントログのうち、下記をCloudWatch Logsへ送信します。

fig03.png

種類 イベントID 取得できる内容
接続ログ 1024/1025/1026/1029 接続先のIPまたはサーバ名、接続の成否、接続に使ったユーザー名のハッシュ値
ログオン 4624/4625 端末へのログオンの成功と失敗
プロセス 4688 起動したプログラム、コマンドライン引数、実行したユーザー
PowerShell 4104 実行されたコードの全文

RDPのログは接続される側だけでなく、接続する側にも残ります。このため端末側のログでも接続先が分かります。イベントログは量が多いため、今回は上記のイベントIDだけに絞って送信します。

設定

設定の流れは下記の通りです。

fig02.png

① GPOで監査を有効にする

4688と4104は既定では記録されないため、GPOで有効にします。設定するのは3つで、いずれもコンピューターの構成です。

設定 場所
プロセス作成の監査(成功) セキュリティ設定 > 監査ポリシーの詳細な構成 > 監査ポリシー > 詳細追跡
プロセス作成イベントにコマンド ラインを含める(有効) 管理用テンプレート > システム > 監査プロセスの作成
PowerShell スクリプト ブロックのログ記録を有効にする(有効) 管理用テンプレート > Windows コンポーネント > Windows PowerShell

ss01_gpo.png

適用後、端末を再起動します。

② イベントログに出力されることを確認する

CloudWatch Logsへ送信する前に、端末のイベントログに出力されているかを確認します。端末から接続先サーバへRDPして、出力された内容を確認します。

Get-WinEvent -LogName 'Microsoft-Windows-TerminalServices-RDPClient/Operational' -MaxEvents 5 |
  Select-Object TimeCreated, Id, Message | Format-Table -AutoSize -Wrap
TimeCreated            Id Message
-----------            -- -------
2026/10/06 6:54:40   1024 RDP ClientActiveX がサーバー (10.0.1.217) に接続しようとしています
2026/10/06 6:52:56   1025 RDP ClientActiveX がサーバーに接続しました
2026/10/06 6:52:11   1026 RDP ClientActiveX が切断しました (理由 = 263)

1024に接続先が出力されます。1026の理由コードは、今回の検証では2が正常な切断、263がログイン失敗、516が接続先に到達できなかった場合でした。

③ Systems Managerに端末を登録する

EC2以外の端末は、ハイブリッドアクティベーションでSystems Managerの管理対象にします。アクティベーションを作成し、発行されたコードを使って端末にSSM Agentをインストールします。

aws ssm create-activation --region ap-northeast-1 `
  --default-instance-name "WS-TEST01" `
  --iam-role "ssm-hybrid-role"

登録できると、マネージドノードとして一覧に表示されます。

aws ssm describe-instance-information --region ap-northeast-1 `
  --query "InstanceInformationList[?starts_with(InstanceId,'mi-')].{Id:InstanceId,Name:ComputerName,Ping:PingStatus}" `
  --output table

-----------------------------------------------------
|            DescribeInstanceInformation            |
+----------------------+-------------+--------------+
|          Id          |    Name     |     Ping     |
+----------------------+-------------+--------------+
|  mi-xxxxxxxxxxxxxxxxx|  WS-TEST01  |  Online      |
+----------------------+-------------+--------------+

④ CloudWatch Logsのロググループを作成する

イベントログの種類ごとにロググループを作成し、保持期間を指定します。

$region = 'ap-northeast-1'
foreach ($g in @('/term/rdp-client','/term/security','/term/process','/term/powershell')) {
  aws logs create-log-group --log-group-name $g --region $region
  aws logs put-retention-policy --log-group-name $g --retention-in-days 400 --region $region
}

端末からCloudWatch Logsに書き込みを行うため、ハイブリッドアクティベーションで使用するIAMロールに下記の権限を追加しておきます。

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "logs:CreateLogStream",
        "logs:PutLogEvents",
        "logs:DescribeLogStreams"
      ],
      "Resource": "arn:aws:logs:ap-northeast-1:123456789012:log-group:/term/*"
    }
  ]
}

⑤ CloudWatch Agentを入れる

Systems Managerの管理対象になっているため、SSMコマンドを使用してCloudWatch Agentのインストールを行います。

aws ssm send-command --region ap-northeast-1 `
  --document-name "AWS-ConfigureAWSPackage" `
  --targets "Key=InstanceIds,Values=mi-xxxxxxxxxxxxxxxxx" `
  --parameters "action=Install,name=AmazonCloudWatchAgent"

⑥ CloudWatch Agentの設定ファイルを記述する

CloudWatch Logsへ送信するイベントIDをevent_idsで指定します。

{
  "logs": {
    "logs_collected": {
      "windows_events": {
        "collect_list": [
          {
            "event_name": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
            "event_ids": [1024, 1025, 1026, 1029],
            "log_group_name": "/term/rdp-client",
            "log_stream_name": "{local_hostname}",
            "event_format": "xml"
          },
          {
            "event_name": "Security",
            "event_ids": [4624, 4625],
            "log_group_name": "/term/security",
            "log_stream_name": "{local_hostname}",
            "event_format": "xml"
          },
          {
            "event_name": "Security",
            "event_ids": [4688],
            "filters": [
              { "type": "exclude", "expression": "Name='SubjectUserSid'>S-1-5-(18|19|20)<" }
            ],
            "log_group_name": "/term/process",
            "log_stream_name": "{local_hostname}",
            "event_format": "xml"
          },
          {
            "event_name": "Microsoft-Windows-PowerShell/Operational",
            "event_ids": [4104],
            "log_group_name": "/term/powershell",
            "log_stream_name": "{local_hostname}",
            "event_format": "xml"
          }
        ]
      }
    }
  }
}

⑦ CloudWatch Agentを起動する

オンプレミスモードで起動します。

$ctl = 'C:\Program Files\Amazon\AmazonCloudWatchAgent\amazon-cloudwatch-agent-ctl.ps1'
& $ctl -a fetch-config -m onPremise -s -c "file:C:\temp\cwagent-config.json"
& $ctl -m onPremise -a status
{
  "status": "running",
  "configstatus": "configured",
  "version": "1.300073.0b1828"
}

runningかつconfiguredになれば送信が始まります。

オンプレミスモードでは認証情報とリージョンの指定が必要です。ハイブリッドアクティベーションで登録した端末では、SSM Agentがロールの一時認証情報をC:\Windows\System32\config\systemprofile\.aws\credentialsに書き込んでいるため、これを読ませます。

$dir = 'C:\Windows\System32\config\systemprofile\.aws'
Set-Content -Path "$dir\config" -Value "[default]`r`nregion = ap-northeast-1" -Encoding ascii

Add-Content -Path 'C:\ProgramData\Amazon\AmazonCloudWatchAgent\common-config.toml' -Encoding ascii -Value @'

[credentials]
   shared_credential_profile = "default"
   shared_credential_file = "C:\\Windows\\System32\\config\\systemprofile\\.aws\\credentials"
'@

⑧ CloudWatch Logsに送信されたログの内容を確認する

送信された接続ログ(1024)です。

<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'>
  <System>
    <EventID>1024</EventID>
    <TimeCreated SystemTime='2026-10-06T06:47:49.2197221Z'/>
    <Channel>Microsoft-Windows-TerminalServices-RDPClient/Operational</Channel>
    <Computer>WS-TEST01.example.local</Computer>
    <Security UserID='S-1-5-21-xxxxxxxxxx-xxxxxxxxxx-xxxxxxxxxx-1112'/>
  </System>
  <EventData>
    <Data Name='Name'>Server Name</Data>
    <Data Name='Value'>10.0.1.217</Data>
  </EventData>
</Event>

1件のイベントで、いつ(TimeCreated)、どの端末から(Computer)、誰が(Security UserIDのSID)、どこへ接続したか(Value)が分かります。SIDはGet-ADUserでユーザー名に戻せます。

今回の設定では取得できないもの

  • 保守対象サーバの中での操作
  • 画面に表示された内容
  • ファイルのコピーや削除、USBへの持ち出し
  • コマンドプロンプトで実行したコマンド

今回の設定で取得できるのは、起動したプログラムとPowerShellで実行したコードまでになります。ファイル操作はオブジェクトアクセスの監査(4663)、USBの接続は6416で記録できるため、監査設定と送信するイベントIDを追加すれば取得できる場合があります。

おわりに

Windows端末の接続ログと操作ログを、AWSの標準機能だけでCloudWatch Logsに集められることが確認できました。RDPのログは接続する側にも残るため、接続先と実行したユーザーは端末側のログでも分かります。接続ログとログオンは既定で記録されており、GPOで監査を有効にすれば、プロセスの起動やPowerShellで実行したコードも取得できます。

3
2
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
3
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?