FSSO not working with 'Poll windows event logs"
Hi
Fortgate 3240C v5.2.7
Windows Server 2012R2 running Collector agent v5.0.0247
Various Win 7 & 8 clients and Macs
Due to having a number of Macs on our domain I can't use DC agents as when users authenticate on the Macs the collector agent does not pick them up. So I need to use the second option "Check Windows Security Event logs", however when I use this option all I see is a list
However with the second option selected I don't see any login events instead I just see any entry in collector log:
08/23/2016 15:36:45 [ 5888] logon event(29506): len:54 dc_ip:x.x.x.x time:1471963005 len:41 data:server-name/KEEPALIVE/Polling ip:255.255.255.255
With the option set to "Poll logon sessions using Windows NetAPI" I can see the logon events in the log file:
action:update_entry workstation:x.x.x.x ip:x.x.x.x:0.0.0.0 user:OCC\<user name>
I have been through and checked open ports on the servers, service account etc with no luck.
Any ideas as to why the second option is not working?
Thanks
Ian