nagios LS is not receiving Microsoft event id 4625 anymore !

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
oliviergautreau
Posts: 11
Joined: Tue Mar 31, 2020 9:22 am

nagios LS is not receiving Microsoft event id 4625 anymore !

Post by oliviergautreau »

Nagios LS is not receiving Microsoft netlogon event id 4625 anymore !

Hi there,

We didn't know when the Problem started and if Microsoft has changed something recently, but our nagios ls dashboard are suddently desperately empty.

Indeed, lots of fields are missing in the messages. Not only net logon event id 4625 is missing, 4624 eventid also, and the TargetUserName, TargetDomainName fields...
Only the windows hosts are concerned, other reports are still ok.
Nxlogs clients are still running and are connected. Nagios LS still receives messages from the hosts, but less than it uses to.

Did someone allready experienced this ?

Could this be linked with this : How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472
https://support.microsoft.com/en-us/hel ... ions-assoc

Thx for your help, Olivier
You do not have the required permissions to view the files attached to this post.
User avatar
cdienger
Support Tech
Posts: 5045
Joined: Tue Feb 07, 2017 11:26 am

Re: nagios LS is not receiving Microsoft event id 4625 anymo

Post by cdienger »

A ticket has been open to address this issue so we will lock this thread and continue troubleshooting through the ticket.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
Locked