What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags


View all Tags

Error Code 1314 - required privilege is not held by the client

Votes:

0

Hi, had a sensor probe checking for security audit event id 4070 to flag account lockouts within AD on all my DCs across the domain. All working fine until yday. Above message is appearing, any ideas on where to start investigating?

active-directory-group security wmi-sensors

Created on Jun 10, 2021 2:55:52 PM



13 Replies

Votes:

0

Hello,

What PRTG version are you currently using?
What sensor shows this error? You can see the sensor type in it's Overview tab on the right side.


Kind regards,
Sasa Ignjatovic, Tech Support Team

Created on Jun 14, 2021 7:31:33 AM by  Sasa Ignjatovic [Paessler Support]



Votes:

0

Hi,

21.2.1

its an event log (Windows API) sensor. Its monitoring security events for event id 4070

other windows api sensors on the same server are working, only this sensor has stopped working. Any server that has this sensor setup has stopped working overnight. its setup on each Domain Controller to catch active directory user account lockouts

thanks,

Created on Jun 15, 2021 8:39:10 AM



Votes:

0

version is 21.2.1

Event log (Windows API)

Created on Jun 15, 2021 8:41:41 AM



Votes:

0

Did you perhaps install any recent windows updates?
We have cases where the security hardening changes relating to Event Tracing for Windows (ETW) for CVE-2021-31958 cause the Windows API sensor to stop working.

Currently, there is not much we can do about this from our side, a update of the probe and target system to the same patch level might solve the issue.


Kind regards,
Sasa Ignjatovic, Tech Support Team

Created on Jun 15, 2021 10:57:20 AM by  Sasa Ignjatovic [Paessler Support]



Votes:

0

Hi Sasa,

Yes the latest security updates where installed 09/06/21 on both the probe and the target servers. Sensor hasn't worked since. hopefully we here of a solution soon

Created on Jun 16, 2021 9:07:05 AM



Votes:

0

Hello,

Currently we have an internal bugfix ticket open for this issue. We hope to have it fixed as soon as possible. Please check the release notes for the next releases of PRTG to see when this is fixed.

Benjamin Day
[Paessler Support]

Created on Jun 16, 2021 2:03:20 PM by  Benjamin Day [Paessler Support] (1,441) 2 1



Votes:

0

Same issue on our side as well

Created on Jun 17, 2021 6:31:57 AM



Votes:

0

Hi,

I have the same issue here. I only want to be alerted when critical events occur on my servers... Please update this KB if a fix is available or if a workaround is found.

Thanks,

Created on Jun 28, 2021 1:58:21 PM



Votes:

0

This is only impacting the Windows API Eventlog sensor. The WMI Eventlog sensor is not impacted by this. If you are only filtering for a single event ID, then I would recommend switching to the WMI variant of the sensor as it will work fine. If you have a need for filtering on multiple event IDs, then you will need to wait for a fix to the Windows API.

Apologies for this inconvenience, but we are at the mercy of Microsoft when it comes to patches they roll out.

Benjamin Day
[Paessler Support]

Created on Jun 28, 2021 7:02:51 PM by  Benjamin Day [Paessler Support] (1,441) 2 1



Votes:

0

Any news about that issue? Still not able to monitor my servers with the Windows API Eventlog sensor. Thank you,

Created on Jul 22, 2021 3:44:20 PM



Votes:

0

We are still working on a fix.

Benjamin Day
[Paessler Support]

Created on Jul 22, 2021 4:51:17 PM by  Benjamin Day [Paessler Support] (1,441) 2 1



Votes:

0

Hello guys!

I've had this problem after installing the latest updates aswell...

So I've tried to find other solution, such as forwarding the logs from my source machine to the PRTG probe using the Windows Event Viewer.

Since the eventViewer subscription needs some settings to work, my PRTG Sensor got back from the dead as I was configuring the Windows Event Forwarding.

What I did is this:

On the Source Machine: - Run the "winrm quickconfig" using a elevated CMD and follow trought with a couple of confirmations; - Add the PRTG Computer account in the Administrator group (windows lusrmgr.msc) of the Source Machine; - Add the "NETWORK SERVICE" account in the Event Log Readers group;

On the PRTG Server: Run "wecutil qc" using a elevated CMD and follow trought with a couple of confirmations;

That's what I was doing when the sensor got back to work...

Don't ask exactly what did the trick, I honestly don't know... hahaha

Created on Aug 17, 2021 8:52:27 PM



Votes:

0

Robson,

Thanks for the information!!

Benjamin Day
[Paessler Support]

Created on Aug 19, 2021 3:57:21 AM by  Benjamin Day [Paessler Support] (1,441) 2 1




Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.