- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hi,
we want to establish the Identity Awareness in our Check Point Firewall. We want to test all possibilities and of course also the Identity Collector.
We activated the function and installed the Collector on one machine. The setup was fairly easy and the connection tests were successful.
Unfortunately the Identity Collector doesn't show any received events even if we use a domain administrator as the account:
Do you have any idea how to troubleshoot that? I would assume that the connection test tells me if there is anything wrong. The firewall on the domain controller allows the access from the Identity Collector.
Maybe your DC doesn't log the right events.
Have a look at sk99006 and check your DC security event log for event IDs 4624, 4768, 4769, 4770.
Thanks for that SK. I will check that today with our admin and report if we were successful.
We have looked at the events and they are collected correctly. Maybe we will look at this some time later but it seems that the Identity Agent is the best solution for us anyway (changing networks etc.).
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY