This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
Parents
  • We do have an issue if the username has a dot . Could you let us know if that is the case with your and also share you log viewer for Authentication componenet.

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • In the syetm log, every 5 minutes this appears - Failed to send firewall information from device to CM


    I believe that you do not need to activate the firewall rule for device, but if I do the endpoint still does not show up. If, I put tick in box for Show Captive Portal for unknown users', I am presented with a login screen when accessing the internet, enter domain user name and password, which verifies, then this endpoint is send in 'Live Users'.

    So the AD part must work to verify (if I put wrong password in it fails). What appears logical to me is, the Endpoint is not passing forward the login detail from within Security Heartbeat.

Reply
  • In the syetm log, every 5 minutes this appears - Failed to send firewall information from device to CM


    I believe that you do not need to activate the firewall rule for device, but if I do the endpoint still does not show up. If, I put tick in box for Show Captive Portal for unknown users', I am presented with a login screen when accessing the internet, enter domain user name and password, which verifies, then this endpoint is send in 'Live Users'.

    So the AD part must work to verify (if I put wrong password in it fails). What appears logical to me is, the Endpoint is not passing forward the login detail from within Security Heartbeat.

Children
No Data