Troubleshoot the passive identity agent

Troubleshoot the passive identity agent software on your Windows AD domain controller or directory server.

This task helps you investigate and resolve user session issues with the passive identity agent by utilizing various troubleshooting methods including log analysis and event viewer investigation.

Procedure


Step 1

Set the log level by opening C:\Program Files\Program Files (x86)\Cisco\Cisco Passive Identity Agent\CiscoPassiveIdentityAgentService.exe.config in a text editor, save the file, and restart the Cisco Passive Identity Agent service.

By default, the passive identity agent logs at the INFO level.

Do not rename C:\Program Files\Program Files (x86)\Cisco\Cisco Passive Identity Agent\CiscoPassiveIdentityAgentService.exe.config ; otherwise, the passive identity agent will stop generating log files. Do not remove or change the .exe.config file extension.

Step 2

Generate troubleshooting files by logging in to the Microsoft Active Directory domain controller.

Step 3

Start the passive identity agent software.

Step 4

Click the Troubleshooting button in the top right corner of the window.

The following figure shows an example.

A confirmation message indicates that the troubleshoot logs have been successfully saved to the system's Downloads folder, with the file name starting with TroubleshootLogs.

The system displays a confirmation message and generates a .zip file containing troubleshooting files.

Your troubleshoot logs are saved to your system's Downloads folder; the file name starts with TroubleshootLogs .

Step 5

Manually view log files stored in plain text format in the agent's installation directory: C:\Program Files\Program Files (x86)\Cisco\Cisco Passive Identity Agent .

Use Notepad or another text editor to view these files. Log files rotate after reaching 10MB in size.

Step 6

Use the Microsoft Active Directory event viewer to look for Kerberos-related events if you are not seeing user sessions in the Cloud-Delivered Firewall Management Center.

Look for the following Kerberos-related events:

For general information about audit policy, see Audit Policy Recommendations on learn.microsoft.com.

For more information about Windows Group Policy Object settings, see Group Policy Objects on learn.microsoft.com.