Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
plindgren
New Contributor

forti collector agent cannot view event log

Hello! I have setup FSSO for windows active directory on my fortigate 100d and on a domain joined server. under User & device > authentication >single sign-on i have my fortinet single sign on agent. and the status shows a green check mark. so the fortigate and the collector agent can speak to each other(if i understand this correctly) But my user field under log & report > traffic log > forward traffic does not populate. I check the collectoragent.log on the collector agent and i get this error: [ 6060] [EPPoller]Could not open the event log on:dc1.domain.local (e=1314) But, when i check " show monitored DCS" i get an increasing amount of logon events. How do i troubleshoot this issue?
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
2 REPLIES 2
plindgren
New Contributor

I have gone abit further in the troubleshooting myself. I have the user " forti" and it is running collectoragent.exe on my domain joined server. When i use that acconunt by opening up a command prompt with it and using wevtutil i can query the eventlog on the dc' s i am monitoring. Still the collector log gets the same error. What settings do i modify to get this working? where do i look to troubleshoot it?
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
plindgren
New Contributor

I solved the issue by changing to netapi instead
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
" This solution needs to be idiot proof!" " Why? Do you plan on hiring idiots?"
Labels
Top Kudoed Authors