Skip to main content
plindgren
New Member
April 24, 2013
Question

forti collector agent cannot view event log

  • April 24, 2013
  • 2 replies
  • 4066 views
Hello! I have setup FSSO for windows active directory on my fortigate 100d and on a domain joined server. under User & device > authentication >single sign-on i have my fortinet single sign on agent. and the status shows a green check mark. so the fortigate and the collector agent can speak to each other(if i understand this correctly) But my user field under log & report > traffic log > forward traffic does not populate. I check the collectoragent.log on the collector agent and i get this error: [ 6060] [EPPoller]Could not open the event log on:dc1.domain.local (e=1314) But, when i check " show monitored DCS" i get an increasing amount of logon events. How do i troubleshoot this issue?

    2 replies

    plindgren
    plindgrenAuthor
    New Member
    May 3, 2013
    I have gone abit further in the troubleshooting myself. I have the user " forti" and it is running collectoragent.exe on my domain joined server. When i use that acconunt by opening up a command prompt with it and using wevtutil i can query the eventlog on the dc' s i am monitoring. Still the collector log gets the same error. What settings do i modify to get this working? where do i look to troubleshoot it?
    plindgren
    plindgrenAuthor
    New Member
    May 3, 2013
    I solved the issue by changing to netapi instead
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!