Hello to all,
I have faced several issues when installing windows native connectors in Windows Server 2019. I have tested that these issues are faced when arcsight connector version 7.15 to 8.2 are installed.
The issue is that the Windows Native connector does not persistently pull logs from windows endpoints, whether they are in a domain or standalone. I get to see the First Event from some windows endpoints and sometimes it does pull couple of logs but there is no persistency in log collection, and I continuously see the error "ERROR EventLogManager - Couldn't connect to endpoint System.Diagnostics.Eventing.Reader.EventLogException: The RPC server is unavailable".
I have come to this conclusion by installing the WINC connector in the same environment but on Windows Server 2016, where I see no delay or errors or any other issues in log collection. Apart from that there is an issue when ever I want to edit the agent.properties file, I see an error that I do not have the sufficient permissions even though I have the Local Administrator and Domain Administrator privileges.
Kindly advise if anyone else has faced such issues.