<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Collector not receiving events in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151440#M24730</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;using&amp;nbsp;&lt;SPAN&gt;sk108235 and&amp;nbsp;sk122686.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i installed Identity Collector 81.035.0000 on Windows Server 2019.&lt;/P&gt;&lt;P&gt;I am successfully connected to ADC servers.&amp;nbsp; I have created a query pool&lt;/P&gt;&lt;P&gt;I'm also successfully connected to one gw running R80.10.&lt;/P&gt;&lt;P&gt;Problem is i'm not seeing any events coming in from the ADC's in the IDC gui.&amp;nbsp; When i clicked on 'logins monitor' and start monitoring, also nothing shows up...&lt;/P&gt;&lt;P&gt;Firewall ports between the IDC server and ADC's are okay.&amp;nbsp; I even disabled fw's on both to be 100% sure.&amp;nbsp; The user account is member of the event log readers.&lt;/P&gt;&lt;P&gt;In the logs i see things like :&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 2200 5492]@SRV[22 Jun 12:00:17] [WinHttpCCC (NAC::IS::TD::Surprise)] UTILS::WinHttpCCC::asyncCallbackMethod: STATUS_REQUEST_ERROR: error 12175 (async API 5) on request (id 1 - 1c1e838)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone having an idea?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 10:20:22 GMT</pubDate>
    <dc:creator>pnobels</dc:creator>
    <dc:date>2022-06-22T10:20:22Z</dc:date>
    <item>
      <title>Identity Collector not receiving events</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151440#M24730</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;using&amp;nbsp;&lt;SPAN&gt;sk108235 and&amp;nbsp;sk122686.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i installed Identity Collector 81.035.0000 on Windows Server 2019.&lt;/P&gt;&lt;P&gt;I am successfully connected to ADC servers.&amp;nbsp; I have created a query pool&lt;/P&gt;&lt;P&gt;I'm also successfully connected to one gw running R80.10.&lt;/P&gt;&lt;P&gt;Problem is i'm not seeing any events coming in from the ADC's in the IDC gui.&amp;nbsp; When i clicked on 'logins monitor' and start monitoring, also nothing shows up...&lt;/P&gt;&lt;P&gt;Firewall ports between the IDC server and ADC's are okay.&amp;nbsp; I even disabled fw's on both to be 100% sure.&amp;nbsp; The user account is member of the event log readers.&lt;/P&gt;&lt;P&gt;In the logs i see things like :&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [Event (NAC::IS::TD::Surprise)] UTILS::Event::wait: Timeout in the wait&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [Exception (NAC::IS::TD::Critical)] UTILS::LoggingException::LoggingException: Operation Timed Out&lt;BR /&gt;[ 2200 4356]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;BR /&gt;[ 2200 4360]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;BR /&gt;[ 2200 4364]@SRV[22 Jun 12:00:07] [PDPChannel (TD::Important)] NAC::IDCOLLECTOR::PDPChannel::run: TimeOutException when waiting on notifiction lock&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 2200 5492]@SRV[22 Jun 12:00:17] [WinHttpCCC (NAC::IS::TD::Surprise)] UTILS::WinHttpCCC::asyncCallbackMethod: STATUS_REQUEST_ERROR: error 12175 (async API 5) on request (id 1 - 1c1e838)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone having an idea?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 10:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151440#M24730</guid>
      <dc:creator>pnobels</dc:creator>
      <dc:date>2022-06-22T10:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector not receiving events</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151445#M24731</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we implemented IA with IC without issues on AD side (we had some glitches with ISE/pxGrid) I have some questions.&lt;/P&gt;
&lt;P&gt;(preferably to answer each one &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;)&lt;/P&gt;
&lt;P&gt;Do you have multiple AD domains/subdomains ?&lt;/P&gt;
&lt;P&gt;The domain you are addressing does have log-in events ?&lt;/P&gt;
&lt;P&gt;Is the account you use allowed to read AD log events ?&lt;/P&gt;
&lt;P&gt;Do you use LDAPs or simple LDAP ? (have you changed the port/checkbox accordingly)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you show s a screenshot of the IC with the AD server/servers you connect to - do you see events counting ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17003iB9E85E954D52B551/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 11:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151445#M24731</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-22T11:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector not receiving events</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151479#M24813</link>
      <description>&lt;P&gt;Do you have multiple AD domains/subdomains ?&amp;nbsp; Only one domain.&lt;/P&gt;&lt;P&gt;The domain you are addressing does have log-in events ?&amp;nbsp; This might be the problem.&amp;nbsp; With log-in events, you mean eventid 4624?&amp;nbsp; I talked to the AD admin and the closest thing i can see is eventid 4776.&amp;nbsp; No 4624.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector-not-getting-any-events/td-p/65440" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector-not-getting-any-events/td-p/65440&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This thread seems to suggest that indeed&amp;nbsp;&lt;SPAN&gt;event IDs 4624, 4768, 4769, 4770 are needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is the account you use allowed to read AD log events ?&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;Do you use LDAPs or simple LDAP ? (have you changed the port/checkbox accordingly)&amp;nbsp; &amp;nbsp;Can't find this setting back but taking into account above this is probably not the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:04:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151479#M24813</guid>
      <dc:creator>pnobels</dc:creator>
      <dc:date>2022-06-22T14:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector not receiving events</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151485#M24814</link>
      <description>&lt;P&gt;Can you have a look here and see if the AD account is created properly , as I know the AD user requirements are like...&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;For AD integration - the Identity Collector requires an AD user that belongs to the default Event Log Readers group.&lt;BR /&gt;No administrative role is required for this user. "&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;(&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector-integration-design-guidelines/m-p/150665?search-action-id=44883405532&amp;amp;search-result-uid=150665" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector-integration-design-guidelines/m-p/150665?search-action-id=44883405532&amp;amp;search-result-uid=150665&lt;/A&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mainly it should be (sk179544):&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: #333333;"&gt;&lt;SPAN&gt;(4) Integrating to Identity Collector - Learning Login Events&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: #ba2454;"&gt;&lt;SPAN&gt;Show / Hide the section&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://youtu.be/tYeOHSbVVCY" target="_blank"&gt;Watch the training video&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;(2 min 30 sec).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN&gt;This video is about:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Integrating Identity Collector to the Active Directory Domain&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Defining Active Directory Domain as an Identity Source&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Adding a Query Pool&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Monitor Login Events&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: #333333;"&gt;&lt;SPAN&gt;(5) Migrating to Identity Collector as identity source in addition to AD Query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: #ba2454;"&gt;&lt;SPAN&gt;Show / Hide the section&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://youtu.be/-CLuxHTewqg" target="_blank"&gt;Watch the training video&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;(3 min 34 sec).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN&gt;This video is about:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Integrating Identity Collector to the Active Directory Domain&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Using ID Collector in parallel to AD Query&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Connecting the ID Collector to the gateway&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: black;"&gt;&lt;SPAN&gt;Monitor ID Sessions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-not-receiving-events/m-p/151485#M24814</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-22T14:18:41Z</dc:date>
    </item>
  </channel>
</rss>

