Windows agent is running properly but is not collecting logs
- Establish a remote connection with the machine running the agent. Open services.msc and verify if the ManageEngine EventLog Analyzer agent service is running.
- On the remote machine:
- Open a web browser and ensure that the EventLog Analyzer web console is accessible.
- Go to the folder under C:\Program Files (x86)\EventLogAnalyzer_Agent\data\zipfiles and check if there are any compressed folders.
- If there are, that implies the agent is collecting logs since the log forwarding has stopped.
- If there aren’t, open the Task Manager and go to the Details tab. Check if SysEvtCol.exe is running. If it isn’t, go to the folder under C:\Program Files (x86)\EventLogAnalyzer_Agent\bin and run the SysEvtCol.exe file.
- Navigate to the file under C:\Program Files (x86)\EventLog Analyzer_Agent\Logs\Agentstatus.out and verify if the server details are correct.
- If they’re not, open the Registry Editor on the device where the agent is installed.
- Go to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ZOHO Corp\EventLogAnalyzer\ServerInfo and update the EventLog Analyzer server details:
- DB Type: Postgres or MSSQL
- IP Address of the server
- Host name of the server
- Web port used to access the UI: Default web port used is 8400
- Protocol used to access the UI: HTTP or HTTPS
New to ADSelfService Plus?
Related Articles
Windows Agent runs fine but not collecting the logs
Remote login to the Agent-installed machine ⇾ open "Services.msc" ⇾ ensure that the "ManageEngine EventLog Analyzer agent" service is running. Remote login to the Agent-installed machine ⇾ open a web browser ⇾ ensure that the EventLog Analyzer Web UI ...
Windows agent service is not running
Establish a remote connection with the machine running the agent. Open services.msc and check if the ManageEngine EventLog Analyzer agent service is running. Open a web browser and ensure that the EventLog Analyzer web console is accessible. Open the ...
Windows Agent version mismatch
Windows Agent version mismatch: Remote login to the Agent-installed machine ⇾ open Registry Editor ⇾ go to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ZOHO Corp\EventLogAnalyzer\LogAgent and ensure that the Agent version matches the Server ...
How do I confirm if the Windows agent is installed properly?
Case 1: Is the configured agent shown in the Devices and Agents pages? In EventLog Analyzer, go to Settings > Devices > Settings > Agents if the configured agent is shown. Case 2: Is the ManageEngine EventLogAnalyzer Agent service present? In the ...
Offline Logs Management
How to: change the Archive (Offline Logs) Location - Applicable for Builds <= 12203 Log on to the EventLog Analyzer UI. Go to Settings Tab ⇾ Admin settings ⇾ Manage Archives ⇾ Settings (right-top corner) Update the new Archive location ⇾ click on ...