For the User Resolution feature to work, the monitoring point designated as the Event Collector must be able to periodically receive login event records from the domain controller. Before it can do this it must be configured to accept a connection request from the domain controller. This capability is controlled from the monitoring point Admin API.

View login event forwarding control

Admin API

  1. Access the Admin API.
  2. Navigate to Access Control > GET /access_control/logfwd/.
  3. Click Try it out.
  4. Click Execute.
    • The Response body field shows the logfwd_enabled configuration. If set to true, the monitoring point is configured to receive login events. If set to false it is not configured to receive these events.

Enable login event forwarding

Admin API

  1. Access the Admin API.
  2. Navigate to Access Control > PUT /access_control/logfwd/.
  3. Click Try it out.
  4. In the body field, specify: “logfwd_enabled”: true.
  5. Click Execute.
    • The Response body field should contain “status”: 200.

Disable login event forwarding

Admin API

  1. Access the Admin API.
  2. Navigate to Access Control > PUT /access_control/logfwd/.
  3. Click Try it out.
  4. In the body field, specify: “logfwd_enabled”: false.
  5. Click Execute.
    • The Response body field should contain “status”: 200.