<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi , Not sure if this helps in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650265#M1028172</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this helps but there is a known bug with v2.2.18 of the UA software which doesn't populate events unless the&amp;nbsp;Date format is set to US Locale on the Domain Controller. I've seen it where events aren't logged at all, or events are generated but only on the first 12 days of the month (I assume theres an issue with the logic on the parser for the logs, once you hit the 13th it bugs out - UK Locale anyway, depends on your date format)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Info here:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;If you use the &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;dd/mm/yyyy &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;date format on your Microsoft Active Directory (AD) server, the system sets the &lt;/FONT&gt;&lt;B&gt;&lt;FONT face="Univers LT 47 CondensedLt,Univers LT 47 CondensedLt" size="2"&gt;&lt;FONT face="Univers LT 47 CondensedLt,Univers LT 47 CondensedLt" size="2"&gt;Active Directory server status &lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT size="2"&gt;to &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;pending &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;and fails to generate events. As a workaround, use the &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;mm/dd/yyyy &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;format on your AD server. (137315) &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other common issues are as you have correctly stated. Ensure the relevant Windows EventIDs for logon/logoff events are generated in the Windows&amp;nbsp;security event logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if the agent and DC/FSM are seperated by a NAT device, you need 2 entries in the User Agents section on the DC/FSM. One for the Pre-NAT address and one for the Post-NAT Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Feb 2015 17:19:27 GMT</pubDate>
    <dc:creator>Scott Cater</dc:creator>
    <dc:date>2015-02-18T17:19:27Z</dc:date>
    <item>
      <title>User Agent (DC 5.3, Agent 2.2)</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650258#M1028159</link>
      <description>&lt;P&gt;Having problems with the user agent/AD integration.&amp;nbsp; I have installed the user agent on a Windows 2008 box, it seems to be communicating with the DC servers fine.&amp;nbsp; When going from the agent to the DC is where it seems the problem is.&amp;nbsp; I added the IP on the DC, added the DC on the agent...get nothing.&amp;nbsp; I can telnet to port 3306 on the DC from the user agent machine fine and get the Got packets out of order message like is said in the troubleshooting guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&amp;nbsp; I turned on debugging and logging on the agent and there are no errors listed and it says start DC chk, end DC chk...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650258#M1028159</guid>
      <dc:creator>nathan.ollis</dc:creator>
      <dc:date>2019-03-12T12:37:01Z</dc:date>
    </item>
    <item>
      <title>So I figured out that it does</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650259#M1028161</link>
      <description>&lt;P&gt;So I figured out that it does actually connect to the DC...just no users populate.&amp;nbsp; Now on to figuring that out...from the logs it looks like the agent is actually only polling the DC and User Agent.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 14:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650259#M1028161</guid>
      <dc:creator>nathan.ollis</dc:creator>
      <dc:date>2015-02-03T14:34:07Z</dc:date>
    </item>
    <item>
      <title>I'm seeing the same issue.I</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650260#M1028162</link>
      <description>&lt;P&gt;I'm seeing the same issue.&lt;/P&gt;&lt;P&gt;I'll be&amp;nbsp;interested to hear if you're able to resolve it.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 14:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650260#M1028162</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-02-07T14:20:31Z</dc:date>
    </item>
    <item>
      <title>I am getting no where.</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650261#M1028165</link>
      <description>&lt;P&gt;I am getting no where. &amp;nbsp;Sourcefire tech support has went around in circles, asking me to check the configuration guides. &amp;nbsp;The thing about it is, I can try a domain admin account and it still not work...which that is the majority of the guide. &amp;nbsp;The tech agreed that there is no reason for it not to work with a domain admin account...on third day waiting for a response now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I found was that we did not have logon event auditing enabled. &amp;nbsp;I really thought that was the issue...&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 12:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650261#M1028165</guid>
      <dc:creator>nathan.ollis</dc:creator>
      <dc:date>2015-02-10T12:21:48Z</dc:date>
    </item>
    <item>
      <title>I had the same problem and</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650262#M1028166</link>
      <description>&lt;P&gt;I had the same problem and unfortunately didnt find the answer , i installed in a win 2012 and its working now,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 14:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650262#M1028166</guid>
      <dc:creator>Eduardo Ferreira Fernandez</dc:creator>
      <dc:date>2015-02-10T14:16:35Z</dc:date>
    </item>
    <item>
      <title>We actually have 2012 on one</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650263#M1028168</link>
      <description>&lt;P&gt;We actually have 2012 on one box, still got nothing from it.&amp;nbsp; Did you install the client on the DC itself?&amp;nbsp; I am trying to go from a Server 2008 box with the UA, connecting to the DC remotely.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 14:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650263#M1028168</guid>
      <dc:creator>nathan.ollis</dc:creator>
      <dc:date>2015-02-10T14:51:51Z</dc:date>
    </item>
    <item>
      <title>I had the same problem but it</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650264#M1028171</link>
      <description>&lt;P&gt;I had the same problem but it started working over the weekend.&amp;nbsp; I have the agent installed on a app server and it reports that things are working connecting to our AD Servers and to Firesight.&lt;/P&gt;&lt;P&gt;Go to analysis -&amp;gt; users -&amp;gt; User Activity.&amp;nbsp; I think I was getting data there but it wasn't matching.&amp;nbsp; I watched a couple videos from &lt;A href="http://www.labminutes.com/video/sec/ASA%20FirePower" target="_blank"&gt;http://www.labminutes.com/video/sec/ASA%20FirePower&lt;/A&gt; and configured some of the access rules to process more data then all my charts started populating.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 15:33:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650264#M1028171</guid>
      <dc:creator>ecornwell</dc:creator>
      <dc:date>2015-02-10T15:33:20Z</dc:date>
    </item>
    <item>
      <title>Hi , Not sure if this helps</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650265#M1028172</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this helps but there is a known bug with v2.2.18 of the UA software which doesn't populate events unless the&amp;nbsp;Date format is set to US Locale on the Domain Controller. I've seen it where events aren't logged at all, or events are generated but only on the first 12 days of the month (I assume theres an issue with the logic on the parser for the logs, once you hit the 13th it bugs out - UK Locale anyway, depends on your date format)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Info here:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;If you use the &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;dd/mm/yyyy &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;date format on your Microsoft Active Directory (AD) server, the system sets the &lt;/FONT&gt;&lt;B&gt;&lt;FONT face="Univers LT 47 CondensedLt,Univers LT 47 CondensedLt" size="2"&gt;&lt;FONT face="Univers LT 47 CondensedLt,Univers LT 47 CondensedLt" size="2"&gt;Active Directory server status &lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT size="2"&gt;to &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;pending &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;and fails to generate events. As a workaround, use the &lt;/FONT&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;&lt;FONT face="Lucida Console,Lucida Console" size="1"&gt;mm/dd/yyyy &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size="2"&gt;format on your AD server. (137315) &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other common issues are as you have correctly stated. Ensure the relevant Windows EventIDs for logon/logoff events are generated in the Windows&amp;nbsp;security event logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if the agent and DC/FSM are seperated by a NAT device, you need 2 entries in the User Agents section on the DC/FSM. One for the Pre-NAT address and one for the Post-NAT Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 17:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650265#M1028172</guid>
      <dc:creator>Scott Cater</dc:creator>
      <dc:date>2015-02-18T17:19:27Z</dc:date>
    </item>
    <item>
      <title>Do not know if you finally</title>
      <link>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650266#M1028174</link>
      <description>&lt;P&gt;Do not know if you finally got yours to work. &amp;nbsp;Ours was an auditing problem on the Domain Controller. &amp;nbsp;If you do not have to log logon and logoff events on all of your DCs...it will not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully you are good by now though...&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 11:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-agent-dc-5-3-agent-2-2/m-p/2650266#M1028174</guid>
      <dc:creator>nathan.ollis</dc:creator>
      <dc:date>2015-07-15T11:53:22Z</dc:date>
    </item>
  </channel>
</rss>

