User-ID Agent Errors on Domain Controllers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

User-ID Agent Errors on Domain Controllers

L3 Networker

I'm getting the following error showing up in event viewer on our Windows domain controller.  We have 4 DC total that have the the user-id agent installed.

dcom_error.PNG

As you can see, I am getting a lot of these error.  The IP in question is one from our BYOD subnet, meaning it could be a end-user personal device.  Most of the IPs in the error logs are from this subnet.

I am also seeing the following on the User-Agent logs:

user-agent_error.PNG

I'm not sure if they are related or not.  When I setup the agent, I left all settings at their defaults, except for adding our service account for start-up and adding the other DCs.

1 accepted solution

Accepted Solutions

L2 Linker

Hello Dannon,

The DCOM errors are most probably due to WMI probing for IPs that are not responding. Can you please disable WMI probing under user-ID setup and test to see if the system error messages stopped ?

On PAN User-ID agent, go to setup --> click edit --> client probing --> uncheck WMI probing checkbox

Helpful doc:

User-ID Agent Generating DCOM and Kerberos System Errors

View solution in original post

3 REPLIES 3

L2 Linker

Hello Dannon,

The DCOM errors are most probably due to WMI probing for IPs that are not responding. Can you please disable WMI probing under user-ID setup and test to see if the system error messages stopped ?

On PAN User-ID agent, go to setup --> click edit --> client probing --> uncheck WMI probing checkbox

Helpful doc:

User-ID Agent Generating DCOM and Kerberos System Errors

Yes, turning off WMI caused the errors to cease.

My problem now is that I want to have WMI enabled, but my server admin doesn't want all the logs flooded with these entries on the DCs.

What to do?

I've found that we have better results with user-id to ip mapping with having WMI probing enabled.  I turned it on, and told our server admin to calm down.  Smiley Wink  It's still messy looking and I would like to have Palo put this in a separate application log in event viewer.  I've seen other filtering software do this.

Dannon

  • 1 accepted solution
  • 6115 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!