<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows DC 10036 Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dc-10036-error/m-p/570690#M114986</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/496997971"&gt;@Kyle_Clifton&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You're likely still using WMI and have actually upgraded the ADDCs that you're polling for logs. You can modify things to use WinRM over HTTP/S and you'll be perfectly fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Dec 2023 21:48:10 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-12-21T21:48:10Z</dc:date>
    <item>
      <title>Windows DC 10036 Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dc-10036-error/m-p/570538#M114969</link>
      <description>&lt;P&gt;The server-side authentication level policy does not allow the user Domain\pafw SID (S-1-5-21-3296291719-1816596347-2220831235-9844) from address 192.168.*.* to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This event triggers on the DC about everyone 2 seconds.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have no experience in PA, I was wondering if someone could explain the Event to me, and maybe how I can stop having it trigger.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 22:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dc-10036-error/m-p/570538#M114969</guid>
      <dc:creator>Kyle_Clifton</dc:creator>
      <dc:date>2023-12-20T22:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DC 10036 Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dc-10036-error/m-p/570690#M114986</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/496997971"&gt;@Kyle_Clifton&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You're likely still using WMI and have actually upgraded the ADDCs that you're polling for logs. You can modify things to use WinRM over HTTP/S and you'll be perfectly fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 21:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dc-10036-error/m-p/570690#M114986</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-12-21T21:48:10Z</dc:date>
    </item>
  </channel>
</rss>

