Created on 
    
	
		
		
		04-11-2022
	
		
		02:48 PM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		02-25-2025
	
		
		02:04 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		 Anthony_E
		
			Anthony_E
		
		
		
		
		
		
		
		
	
			 
		
| Description | This article describes how the FSSO Collector Agent performs name resolution of the workstation as a part of forming the logon event. | 
| Scope | FSSO Collector Agent. | 
| Solution | If the collector Agent gets the username and workstation name ( either from the DC agent or security event log ), as a part of forming the fsso logon for the given user, the FSSO collector agent has to resolve the workstation name to get the current IP address of the workstation from which the user is logged in. 
 The FSSO name resolution logic works in this order: 
 
 
 
 
 
 
 Example: 
 04/04/2022 15:28:10 [ 3708] DnsQuery() failed for JSMITH.test.lab, error code:9501 
 
 OS might resolve the name using one of these possible ways: 
 
 Example: 
 04/04/2022 15:28:10 [ 3708] resolve_ip_internal: dns look up failed, call gethostbyname():JSMITH.test.lab 
 FSSO Collector agent does not have any control nor can influence the name resolution in that case. If this step also fails, move to step 4. 
 
 
 
 Related articles: | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.