Skip to main content
Ian_Harrison
New Member
August 23, 2016
Question

FSSO not working with 'Poll windows event logs"

  • August 23, 2016
  • 4 replies
  • 15411 views

Hi

 

Fortgate 3240C v5.2.7

Windows Server 2012R2 running Collector agent v5.0.0247

Various Win 7 & 8 clients and Macs

 

Due to having a number of Macs on our domain I can't use DC agents as when users authenticate on the Macs the collector agent does not pick them up.  So I need to use the second option "Check Windows Security Event logs", however when I use this option all I see is a list

 

However with the second option selected I don't see any login events instead I just see any entry in collector log:

08/23/2016 15:36:45 [ 5888] logon event(29506): len:54 dc_ip:x.x.x.x time:1471963005 len:41 data:server-name/KEEPALIVE/Polling ip:255.255.255.255

 

With the option set to "Poll logon sessions using Windows NetAPI" I can see the logon events in the log file:

action:update_entry workstation:x.x.x.x ip:x.x.x.x:0.0.0.0 user:OCC\<user name>

 

I have been through and checked open ports on the servers, service account etc with no luck.

 

Any ideas as to why the second option is not working?

 

Thanks

 

Ian

    4 replies

    MrSinners
    New Member
    August 25, 2016

    What happens when using the Polling Event logs with WMI option (third one)? This one is the recommended option to use.

     

    Are there errors in the Windows Server event logs visible?

     

    Are you sure the agent is installed with an account that has enough permissions to read the event log? Maybe try a full domain admin account as a test to ensure this is not the issue.

     

    Also there is a newer agent available that can be used, namely v5.0.0250 (which can be found in the download map for 5.2.8).

     

    Also there are some requirements that are not that easy to find. For example, all workstations have to be resolvable in DNS by the agent, and remote registry has to be enabled via ports 139 or 445. This only applies to Windows machines, I don't know if this works with Macs.

    xsilver_FTNT
    Staff
    Staff
    August 29, 2016

    Hello,

    if I got it correctly then when you do WinSec polling you do not see any users in FSSO user list on Collector.

    If so, then check if monitored/polled DCs actually do audit logon events. It is common issue that audit is disabled and so WinSec do not contain necessary data. I would start there.

    See GPO screenshot from my lab Win2008-R2 - https://dl.dropboxusercontent.com/u/25571346/2008_WIN_Audit_Sec_Events_HowTo.png

     

    shaun23
    New Member
    January 19, 2018

    Hi Tomas,

     

    Can you repost the dropbox link please?

     

    Cheers

    Shaun

    xsilver_FTNT
    Staff
    Staff
    January 22, 2018
    oguzhan_aygoren
    New Member
    February 21, 2022

    Hello,
    Is this case solved. Can you help me?

    -> I checked this parameters,

    --> fortigate verison is 6.4.8

    --> fsso version is 5.0.0302_x64

    --> fsso user is admin

     

     

     

    Debbie_FTNT
    Staff & Editor
    Staff & Editor
    February 23, 2022

    Hey oghuzan,

    thanks for sharing the information. Can you elaborate a little?

    - have you tried the different polling methods? (WMI, NetAPI)

    - if yes, did any of them work?

    - have you verified that your domain controllers are auditing login events?

    -> the domain controllers must have login events in their windows security event logs in the first place for Collector Agent to pick up anything

    - are you polling only some or all domain controllers in your environment?

    - do you get any errors in the Collector Agent debug log?

    - do you get any users in the Login User List on Collector Agent?

    Markus_M
    Staff & Editor
    Staff & Editor
    February 22, 2022

    Hey,

     

    you might want to specify your question. The thread here is past its fifth birthday, it is unlikely that this is the same issue. Many things, even on AD side have changed.

     

    Best regards,

     

    Markus