Additional Prerequisites for the Windows Event Log Collector
- The Cisco AD Connector account (Cisco_Connector or custom account as configured) should be added to the local Event Log Readers group on the Windows Event Log Collector machine.
- On the Windows Event Log Collector machine, enable these firewall rules, which allow the server where you deployed the AD Connector to read the Windows event logs:
- Remote Event Log Management (NP-In)
- Remote Event Log Management (RPC)
- Remote Event Log Management (RPC-EPMAP)
- Review all network access requirements. For more information, see AD Connector Communication Flow and Troubleshooting.