Description
Solution
1) Open the Registry Editor (regedit) and go to HKEY_LOCAL_MACHINE ->SOFTWARE ->Fortinet ->FSAE ->DCAgent then right click on enable_log and modify.
2) Change the value data to 1 to enable DC-Agent logging.
The DC-Agent log should look like the following example:
reload configuration from registry
Failed to read donot_resolve
Failed to read no_keepalive
Failed to read domain_DNSsuffix
read collector agent:10.0.0.10 port:8002 return code:0 index:0
read collector agent:10.0.0.253 port:8002 return code:0 index:1
version:5.0.0278, donot_resolve flag:0 no_keepalive flag:0 log file:c:\dcagentlog.txt ignore list:MT-TEST\sdx_*;MT-TEST\Administrator; domain:MT-TEST (mt-test.local)
collector agent:10.0.0.10 port:8002
collector agent:10.0.0.253 port:8002
11/06/2019 14:22:15.773: finish processing.
Msv1_0SubAuthenticationFilter is called
11/06/2019 14:22:15.836: processing Logon (level=1, logonid=0-0) MT-TEST\MT-TEST_FAC$ () from (null)
Ignore logon event without workstation information.
11/06/2019 14:22:15.836: finish processing.
Msv1_0SubAuthenticationFilter is called
11/06/2019 14:22:18.908: processing Logon (level=1, logonid=0-0) MT-TEST\syntest (syn test) from PC-TEST
Domain:MT-TEST DNS suffix added:mt-test.local.
workstation IP:10.0.0.51
11/06/2019 14:22:18.908: finish processing.
Note: Log file size is hardcoded to 10MB and not configurable as it is on Collector Agent.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.