Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lekanhaji
New Contributor

FSSO Ignore user list - automation

We currently use the FSSO ignore list for service accounts, but have to manually sync everytime we create new account then sync it with the other agents on other sites, is there a way to automate this process?

10.0.0.0.1 192.168.1.254
2 REPLIES 2
akanibek
Staff
Staff

@lekanhaji,

I guess there are no options to script it. However, syncing from one FSSO CA to others also somehow facilitates.

Asset
Debbie_FTNT
Staff
Staff

Hey lekanhaji,

 

technically, the ignore user list is stored in registry keys:

[HKEY_LOCAL_MACHINE\software\wow6432node\fortinet\fsae\collectoragent\Filter]

The key is of type string, called "ignore_users", consists of a list of ignored users, and the user entries are separated by semicolon.

 

You could use GPOs (or similar tools) to update the registry keys across all hosts with Collector Agents.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors