I am setting up backup user-id agent 8.1.10-2 on Windows 2016 Standard server.
I have given all the required access to the user-id agent admin account but its not working / refusing to start.
I am using the same credential on existing UID agent 7.0.8-13 running on Windows 2008 R2 and it runs fine.
I attaching error messgae when starting UID service and corresponding log generated in UID logs.
09/05/19 09:42:52:190[ Info 2357]: ------------Service is being started------------
09/05/19 09:42:52:190[ Info 2364]: Os version is 6.2.0.
09/05/19 09:42:52:190[Error 675]: Cannot open config reg log key with error 5(Access is denied.
09/05/19 09:42:52:190[Error 2382]: Start error -1!!
09/05/19 09:42:52:190[Error 764]: Device listening thread stops timeout
Please note that Palo Alto has a mistake in the latest versions of the documentation.
Step 1, Section 4, Bullet 1 -
This cost me about 4 hours this evening trying to figure out why I was getting the same "Cannot open config reg log key with error 5(Access is denied." error. Hopefully it saves someone else some time in the future. The other article referenced above does say it could be "EITHER" of these two locations. However, for me that was incorrect. I stopped looking when I found the first location, but both registry locations actually existed. The first one is related to Global Protect and appears to have no effect on the User ID Agent service. I am running it by only setting permissions on the second location I provided.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!