The following configuration steps are mandatory for multi-DC setups to fetch events from other Domain Controllers. Single-DC environments do not require these configuration steps.
Step 1: Verify the Multi-DC Environment
Run the following PowerShell command to list all Domain Controllers and confirm the multi-DC setup:
Get-ADDomainController -Filter * | Select-Object Name, IPv4Address, OperatingSystem, Site
Step 2: Check Existing Firewall Rules
Verify the current firewall rules for Remote Event Log Management on all DCs. If access is not allowed, the Enabled status will return as False.
Get-NetFirewallRule -DisplayGroup "Remote Event Log Management" | Select-Object Name, Enabled, Action
Step 3: Enable Firewall Rules for Event Log Management
Run the following command on all Domain Controllers to enable access:
netsh advfirewall firewall set rule group="Remote Event Log Management" new enable=yes
Step 4: Verify the Firewall Rule Changes
Run the verification command again on all DCs to ensure the rules are now successfully applied. The Enabled status should now return as True.
Get-NetFirewallRule -DisplayGroup "Remote Event Log Management" | Select-Object Name, Enabled, Action
Step 5: Configure the Druva-ActiveDirectory Service Account
To successfully fetch events from other DCs, update the service logon credentials:
Open the Services app (
services.msc).Locate the Druva-ActiveDirectory Service.
Right-click the service and select Properties, then navigate to the Log On tab.
Change the Log-on type from Local System Account to This account.
Provide the credentials for a specific Domain Administrator account.
Restart the service to apply the changes.
Alternative Method for Step 5: Grant Local System Account Access via AD Group
Add the computer account of the DC (For example, <Hostname>$) to the "Event Log Readers" Active Directory group.
Commands (Using placeholder <DC-Hostname>):
Check if the DC is already in the Event Log Readers group.
Get-ADGroupMember "Event Log Readers" | Where-Object { $_.Name -eq "<DC-Hostname>" }Add the DC computer account to the group (ensure the $ is appended to the hostname)
Add-ADGroupMember -Identity "Event Log Readers" -Members "<DC-Hostname>$"
Verify if the addition was successful
Get-ADGroupMember "Event Log Readers" | Where-Object { $_.Name -eq "<DC-Hostname>" }
