We use cookies on our website to ensure we provide you with the best experience on our website. By using our website, you agree to the use of cookies for analytics and personalized content.This website uses cookies. More Information
It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda Web Security Service

What Event IDs need to be logged for the DC Agent client to work with the Barracuda Web Security Gateway?

  • Type: Knowledgebase
  • Date changed: 8 years ago

Solution #00004927

 

Scope:
Applies to Barracuda Web Security Flex.

Answer:
In order for the DC Agent client to work with the Barracuda Web Security Gateway, you will have to make sure you are logging the correct Event ID on your Domain Controller in order to capture user login information (username and IP addresses). The following Event IDs are required to be logged in the Event Log of the Domain Controller:
 
Windows Server 2003
Event ID 540: Successful Network Logon
 
Windows Server 2008
Event ID 4624: An account was successfully logged on

Additional Resources:


How to Enable Auditing for Active Directory Objects in Windows Server 2003:
http://support.microsoft.com/kb/814595

Description of Event ID 540 (Windows 2003):
http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=540

How to Enable Active Directory Auditing on Windows Server 2008:
http://www.windowsecurity.com/articles/Windows-Active-Directory-Auditing.html

Description of Event ID 4624 (Windows 2008):
http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4624


Link to this page:

https://campus.barracuda.com/solution/50160000000IIEZAA4