Hi,
I've added two W2012R2 servers to my trial version as file servers. Yet to fetch event data is permanetly displayed. When I select Run now, I'm prompted to refresh the screen to see the status but the data is never fetched.
Steps to troubleshoot this:
- Added a different file server on WS2012R2 - that fetches data immediately.
- Added all the shares to auditing
- Set the SACL via GPO
- Set Object Access policy via GPO
- Ran auditpol.exe /get /category:* to confirm
I've narrowed it down to Windows Firewall configuration setting.
What ports on the Windows firewall need to be open to allow the fetch to work?