we have FSSO Agent running on member server, it pollss the AD server.
when looking at Show Logn Users, most of the users show as Type DC-agent, but a few are showing as type EventLog.
can someone tell me why? my understanding of our setup is it polls the AD server, and those users in certain AD groups are allowed internet based on the group they are in.
so what is EventLog type in that case?
Solved! Go to Solution.
Hi @jamestiberius ,
There are 2 method for FSSO.
Fortigate itself poll from the AD server
vs
Fortigate poll from the DC-Agent which installed on the server.
In your case, maybe you have a combination of it.
Hi @jamestiberius ,
There are 2 method for FSSO.
Fortigate itself poll from the AD server
vs
Fortigate poll from the DC-Agent which installed on the server.
In your case, maybe you have a combination of it.
More info on polling and which node understands what as well as which event IDs are used:
User | Count |
---|---|
2074 | |
1176 | |
770 | |
450 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.