Windows device status: Access denied
The Access denied error indicates that the user account dedicated for log collection does not have the necessary access and permissions to collect logs from the respective devices.
There are two approaches to fixing the error:
- Using a domain admin account
- Using a service account with the necessary privileges
- Using a domain admin account:
- Go to the Settings tab > Configuration > Manage Devices > Windows Devices. Click Update next to the listed device. Enable the Use domain credentials check box, then select Update.
- Go to the Settings > Admin Settings > Domains and Workgroups. Click Update next to the Domain Name. Enter the domain admin credentials, then select Update.
- Using a service account with the necessary privileges:
- Go to Settings > Configuration > Manage Devices > Windows Devices. Click Update next to the listed device. Enable the Use domain credentials check box, then select Update.
- Refer to this guide for step-by-step instructions on configuring a service account.
- You will need the following permissions and privileges to use a service account:
- User groups:
- Event Log Readers
- Distributed COM Users
- User rights to be granted:
- Act as part of the operating system
- Log on as a batch job
- Log on as a service
- Replace a process level token
- Manage Auditing and Security Log Properties
- User permissions to be granted:
- Enable Account
- Remote Enable
- Read Security
- Once you have the necessary privileges, go to Settings > Admin Settings > Domains and Workgroups. Click the update icon in the Actions column. Enter the service account credentials, then select Update.
Windows device status: RPC server is unavailable
The RPC server is unavailable error will be displayed in the device status field if there isn’t any communication between the EventLog Analyzer server and the respective machine from which the logs should be collected. This lack of communication ...
Windows agent status: Unavailable
Establish a remote connection with the machine that the agent is installed on. Open a web browser and ensure that the EventLog Analyzer web UI is accessible. On the remote machine, open the file under C:\Program Files (x86)\EventLog ...
Windows: File Integrity Monitoring (FIM) issues
Prerequisites: An agent needs to be deployed on the respective machine. Open the EventLog Analyzer GUI. Go to the Settings tab > Configuration > Manage File Integrity Monitoring. Configure the folders in the machine that should be monitored. Verify ...
Windows agent service is not running
Establish a remote connection with the machine running the agent. Open services.msc and check if the ManageEngine EventLog Analyzer agent service is running. Open a web browser and ensure that the EventLog Analyzer web console is accessible. Open the ...
Mismatch in the Windows agent version
Establish a remote connection with the machine where the agent is installed. Open the Registry Editor, then go to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ZOHO Corp\EventLogAnalyzer\LogAgent and ensure that the agent version matches the ...