Created on 06-07-2016 05:24 AM Edited on 08-31-2024 10:24 AM By Stephen_G
Description
This article illustrates how and why to use the FSSO Collector Agent ‘Ignore User List’ option.
Solution
In principle, FSSO Collector Agents capture all (user) account logins generated on monitored Domain Controllers, whether in polling mode or DC Agent mode. This includes service accounts and admin accounts as well.
In addition, FSSO only accounts for one user per IP (except for terminal servers and the specific Terminal Server Agent), and the Collector Agent will overwrite an existing login on an IP if another login event on the same IP is observed.
This means, for FSSO to work as expected, it is necessary to exclude certain accounts to prevent login information from being overwritten. Generally, service accounts and some admin accounts need to be excluded to prevent them from overwriting valid user logins when a login event is triggered by a service account or admin. FSSO Collector Agent provides the ‘Ignore User List’ option for this purpose.
Note: Entries added to the Ignore User List on the Collector Agent are also synchronized/pushed to the monitored DC Agents' Ignore User List. This will help to reduce the volume of network traffic being sent from the DC-Agent(s) to the Collector Agent as well as reduce the number of logon events that the DC Agent(s) need to process (see this forum thread for more information ).
To configure the Ignore User List:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.