to attribute traffic from remote desktop service host (windows server 2012 r2) to users we created a test implementation of SATC with sophos server protection.
current issue: nearly all traffic is not assigned to user (username in log empty).
but all requirements seem to be fine:
- user is authenticated (listed under live users as client type = thin client)
- sntpService.log show connections assigend to user with username, session id, ip, source port, dest port
used version:
- XGS3300 (SFOS 19.0.0 GA-Build317)
- Core Agent 2.20.13
- Sophos Intercept X 2021.3.1.11
- Server Protection 10.8.11.4
any ideas what is wrong or how to debug?
This thread was automatically locked due to age.