This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS Agent Insufficient Buffer

Good Morning,

 

I have the STAS Collector installed on a Domain controller and everything seems to be working fine as it is identifying users on the XG. I added the Agent to a second Domain controller, opened the Win F/W ports and can successfully test connectivity between the Agent and Collector and vice versa. However, I am not identifying any users that are authenticating against the second DC. In the log file for the Agent I am receiving the following error and similar variants with different buffer size requirements:

 

ERROR [0x1d64] 7/2/2018 11:13:56 : dca_eventlog: ReadEventLog failed: Insufficient Buffer. Required Buffer size:10008 bytes

It would appear that it is not reading the log on the second DC. Anyone seen anything similar to this before?

Any assistance is greatly appreciated!

 

-dw



This thread was automatically locked due to age.
Parents
  • I've made some progress. Unchecking the "Reduce log" checkbox on the Advanced Tab of the Agent seems to have resolved the Insufficient Buffer errors and according to the logs, I am collecting events now. However, I am still not seeing any identified user activity from the Agent DC on the Firewall. Also if I check the "Show Live Users" on the Collector, no one that was authenticated on the Agent DC is listed. I have turned off the Windows Firewall on both DCs temporarily and still am not seeing identified user activity from the Agent DC.

    Any suggestions on what else to check?

Reply
  • I've made some progress. Unchecking the "Reduce log" checkbox on the Advanced Tab of the Agent seems to have resolved the Insufficient Buffer errors and according to the logs, I am collecting events now. However, I am still not seeing any identified user activity from the Agent DC on the Firewall. Also if I check the "Show Live Users" on the Collector, no one that was authenticated on the Agent DC is listed. I have turned off the Windows Firewall on both DCs temporarily and still am not seeing identified user activity from the Agent DC.

    Any suggestions on what else to check?

Children
No Data