﻿<?xml version="1.0" encoding="utf-8"?><DataCollectorSet><Name>Active Directory Diagnostics</Name><DisplayName>@%systemroot%\system32\ntdsperf.dll,#2000</DisplayName><Keyword>Active Directory Diagnostics</Keyword><Description>@%systemroot%\system32\ntdsperf.dll,#2001</Description><Duration>300</Duration><RootPath>%systemdrive%\perflogs\ADDS</RootPath><SubdirectoryFormat>1</SubdirectoryFormat><SubdirectoryFormatPattern>yyyyMMdd\-NNNN</SubdirectoryFormatPattern><TraceDataCollector><Name>NT Kernel</Name><FileName>NtKernel</FileName><SessionName>NT Kernel Logger</SessionName><ClockType>1</ClockType><BufferSize>64</BufferSize><MaximumBuffers>200</MaximumBuffers><TraceDataProvider><Guid>{9E814AAD-3204-11D2-9A82-006008A86939}</Guid><KeywordsAny><Value>0x00010303</Value></KeywordsAny></TraceDataProvider></TraceDataCollector><TraceDataCollector><DataCollectorType>1</DataCollectorType><Name>Active Directory</Name><FileName>Active Directory</FileName><BufferSize>64</BufferSize><ClockType>1</ClockType><MaximumBuffers>200</MaximumBuffers><TraceDataProvider><DisplayName>Active Directory: Kerberos KDC</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>0</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{24DB8964-E6BC-11D1-916A-0000F8045B04}</Guid></TraceDataProvider><TraceDataProvider><DisplayName>Active Directory: Kerberos Client</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>0</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{BBA3ADD2-C229-4CDB-AE2B-57EB6966B0C4}</Guid></TraceDataProvider><TraceDataProvider><DisplayName>Active Directory Domain Services: Core</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>0</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{1C83B2FC-C04F-11D1-8AFC-00C04FC21914}</Guid></TraceDataProvider><TraceDataProvider><DisplayName>Active Directory Domain Services: SAM</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>2</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{8E598056-8993-11D2-819E-0000F875A064}</Guid></TraceDataProvider><TraceDataProvider><DisplayName>NTLM Security Protocol</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>0</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{C92CF544-91B3-4DC0-8E11-C580339A0BF8}</Guid></TraceDataProvider><TraceDataProvider><DisplayName>Local Security Authority (LSA)</DisplayName><FilterEnabled>0</FilterEnabled><FilterType>0</FilterType><Level><Description>Events up to this level are enabled</Description><ValueMapType>1</ValueMapType><Value>0</Value><ValueMapItem><Key /><Description /><Enabled>-1</Enabled><Value>0x0</Value></ValueMapItem></Level><KeywordsAny><Description>Events with any of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAny><KeywordsAll><Description>Events with all of these keywords are enabled</Description><ValueMapType>2</ValueMapType><Value>0x0</Value></KeywordsAll><Properties><Description>These additional data fields will be collected with each event</Description><ValueMapType>2</ValueMapType><Value>0</Value><ValueMapItem><Key>sid</Key><Description>Security Identifier</Description><Enabled>0</Enabled><Value>0x1</Value></ValueMapItem><ValueMapItem><Key>sessionid</Key><Description>Session Identifier</Description><Enabled>0</Enabled><Value>0x2</Value></ValueMapItem></Properties><Guid>{cc85922f-db41-11d2-9244-006008269001}</Guid></TraceDataProvider></TraceDataCollector><PerformanceCounterDataCollector><Name>Performance Counter</Name><SampleInterval>3</SampleInterval><Counter>\Process(*)\*</Counter><Counter>\DirectoryServices(*)\*</Counter><Counter>\PhysicalDisk(*)\*</Counter><Counter>\Processor(*)\*</Counter><Counter>\Memory\*</Counter><Counter>\System\*</Counter><Counter>\Server\*</Counter><Counter>\Network Interface(*)\*</Counter><Counter>\UDPv4\*</Counter><Counter>\TCPv4\*</Counter><Counter>\IPv4\*</Counter><Counter>\UDPV6\*</Counter><Counter>\TCPv6\*</Counter><Counter>\IPv6\*</Counter></PerformanceCounterDataCollector><ConfigurationDataCollector><Name>AD Registry</Name><QueryNetworkAdapters>-1</QueryNetworkAdapters><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap\ldapclientIntegrity</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kdc\MaxDatagramReplySize</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\DSA Heuristics</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\RID Values\RID Block Size</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\Schema Update Allowed</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\TcpWindowSize</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Tcp1323Opts</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\MaxHashTableSize</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\NumTcbTablePartitions</RegistryKey><RegistryKey>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\MaxUserPort</RegistryKey></ConfigurationDataCollector><DataManager><Enabled>-1</Enabled><CheckBeforeRunning>-1</CheckBeforeRunning><MinFreeDisk>200</MinFreeDisk><MaxSize>1024</MaxSize><MaxFolderCount>100</MaxFolderCount><ResourcePolicy>0</ResourcePolicy><FolderAction><Size>0</Size><Age>1</Age><Actions>3</Actions></FolderAction><FolderAction><Size>0</Size><Age>56</Age><Actions>8</Actions></FolderAction><FolderAction><Size>0</Size><Age>168</Age><Actions>26</Actions></FolderAction><ReportFileName>report.html</ReportFileName><ReportSchema><Report name="wpdcAdvisor" version="1" threshold="9999"><Import file="%systemroot%\pla\reports\Report.System.Common.xml" /><Import file="%systemroot%\pla\reports\Report.System.Summary.xml" /><Import file="%systemroot%\pla\reports\Report.System.Performance.xml" /><Import file="%systemroot%\pla\reports\Report.System.CPU.xml" /><Import file="%systemroot%\pla\reports\Report.System.Network.xml" /><Import file="%systemroot%\pla\reports\Report.System.Disk.xml" /><Import file="%systemroot%\pla\reports\Report.System.Memory.xml" /><Import file="%systemroot%\pla\reports\Report.System.Configuration.xml" /><Import file="%systemroot%\pla\Reports\Report.AD.xml" /></Report></ReportSchema><Rules><Logging level="0" /><Import file="%systemroot%\pla\rules\Rules.System.Common.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Summary.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Performance.xml" /><Import file="%systemroot%\pla\rules\Rules.System.CPU.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Network.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Disk.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Memory.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Configuration.xml" /><Import file="%systemroot%\pla\Rules\Rules.AD.xml" /><Import file="%systemroot%\pla\rules\Rules.System.Finale.xml" /></Rules></DataManager></DataCollectorSet>