Previous Topic: Create a User Account for the Agent

Next Topic: Download Agent Binaries

Grant the Agent-User Access to Windows Security Logs

Administrator-level access for the agent-user is not necessary or recommended. For access to local and remote WMI events, the agent-user should be a least-privileged user account which has the user right, Manage auditing and security log. (This user right is also known as the SeSecurityPrivilege.) You can set this user right for the agent-user in the Local Security Settings, Local Policies area.

To set the local security policy

  1. Access the Control Panel.
  2. Open the Administrative Tools folder.
  3. Double-click the Local Security Policy utility.
  4. Expand the Local Policies node.
  5. Select the User Rights Assignment node, and scroll down through the alphabetical list to the option, Manage auditing and security log.
  6. Double-click Manage auditing and security log.
  7. Click Add User or Group....

    The Select Users or Groups appears.

  8. Enter the name of the agent-user account you created and click Check Names.

    This action verifies that the user account name is populated correctly in the list.

  9. Click OK.