Solved

McAfee SIEM Event Collector 11.0 and Windows 2008 R2 Domain Controller

Posted on 2016-07-19
6
45 Views
Last Modified: 2016-07-29
Has anyone found a way to use the Mcafee SIEM Collector work on a Domain Controller and tail the DNS.log file without making it a Domain Admin. I have been working on this for days trying to figure out what files, folders and registry keys it needs but not luck..

I keep getting the same message: "Failed to start impersonation: 1326" but with the same config works fine under my domain admin account.
0
Comment
Question by:compdigit44
  • 4
6 Comments
 
LVL 33

Expert Comment

by:Busbar
ID: 41721084
It didn't work with us and we created domain admin account
0
 
LVL 19

Author Comment

by:compdigit44
ID: 41721476
This seems SO WRONG TO ME from a security point of view
0
 
LVL 24

Expert Comment

by:Mohammed Khawaja
ID: 41721552
Same here when I tested.   It is kind of funny that a security software requirements goes against most security recommendations.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 19

Author Comment

by:compdigit44
ID: 41722044
Here are my thoughts..

1) Create a domain admin account but only grant it the ability to log into one or two DC's running DNS. yes this account can still access AD from the servers both at least it is not as wide open.

2) From my testing the application does not linke UNC paths or network drives. I was trying to see if I could install the softwrae on anther server and map to the DC folder to read the log file...Even tried a linked directory..  and it did not work...

It has to be something with the registry but do not want to  change anything on a DC.

So the trick is to create a mount point that is really a \\unc path which I know you cannot do BUT wondering if you could trick windows to think the network drive is local

http://superuser.com/questions/812433/can-i-make-a-mapped-network-share-appear-as-a-local-drive
0
 
LVL 19

Accepted Solution

by:
compdigit44 earned 0 total points
ID: 41726665
It looks like there is a way to added a user to the "local administrators " group on a DC....

http://www.richardawilson.com/2010/06/add-user-as-local-administrator-on.html

Hope this helps...
0
 
LVL 19

Author Closing Comment

by:compdigit44
ID: 41734462
Found solution and posted finding for others.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now