Weird Behavior Adding Windows Event Log Sources
Running a pair of 200E's in HA and acting as our only collector for FSSO. We have to remove all our dsagents off our DC's due to a conflict with AuthLite that needs access to the same registry key as dsagent. So I'm going with a combination of Windows Event Log Source polling and FortiClient MSA. Creating event log polling is giving me some trouble. I create a new source pointing to a DC and that works with a service account with correct permissions. It starts reading the logs and working properly.
However as soon as I add another source (a different DC) but using the same credentials that account gets immediately locked out. Before you ask, this is not related to the new Microsoft patch KB5003638 - we are holding off on that. This is truly bizarre. In order for my first source not to stop working I have to unlock the account and delete the new source. My next step is to create a service account related to each DC and see if that works - but that isn't a terrific solution. I'm running 6.0.2 so I know it's a little old. Planning on updating over the weekend, just in case. Did open a TAC case but no joy yet. Any ideas appreciated.
