Skip to main content

Configuration Steps for Multi-Domain Controller (Multi-DC) Environments

The following configuration steps are mandatory for multi-DC setups to fetch events from other Domain Controllers. Single-DC environments do not require these configuration steps.

Step 1: Verify the Multi-DC Environment

Run the following PowerShell command to list all Domain Controllers and confirm the multi-DC setup:

Get-ADDomainController -Filter * | Select-Object Name, IPv4Address, OperatingSystem, Site

Step 2: Check Existing Firewall Rules

Verify the current firewall rules for Remote Event Log Management on all DCs. If access is not allowed, the Enabled status will return as False.

Get-NetFirewallRule -DisplayGroup "Remote Event Log Management" | Select-Object Name, Enabled, Action

Step 3: Enable Firewall Rules for Event Log Management

Run the following command on all Domain Controllers to enable access:

netsh advfirewall firewall set rule group="Remote Event Log Management" new enable=yes

Step 4: Verify the Firewall Rule Changes

Run the verification command again on all DCs to ensure the rules are now successfully applied. The Enabled status should now return as True.

Get-NetFirewallRule -DisplayGroup "Remote Event Log Management" | Select-Object Name, Enabled, Action

Step 5: Configure the Druva-ActiveDirectory Service Account

To successfully fetch events from other DCs, update the service logon credentials:

  1. Open the Services app (services.msc).

  2. Locate the Druva-ActiveDirectory Service.

  3. Right-click the service and select Properties, then navigate to the Log On tab.

  4. Change the Log-on type from Local System Account to This account.

  5. Provide the credentials for a specific Domain Administrator account.

  6. Restart the service to apply the changes.

Alternative Method for Step 5: Grant Local System Account Access via AD Group

Add the computer account of the DC (For example, <Hostname>$) to the "Event Log Readers" Active Directory group.

Commands (Using placeholder <DC-Hostname>):

  1. Check if the DC is already in the Event Log Readers group.

    Get-ADGroupMember "Event Log Readers" | Where-Object { $_.Name -eq "<DC-Hostname>" }

  2. Add the DC computer account to the group (ensure the $ is appended to the hostname)

    Add-ADGroupMember -Identity "Event Log Readers" -Members "<DC-Hostname>$"

  3. Verify if the addition was successful

    Get-ADGroupMember "Event Log Readers" | Where-Object { $_.Name -eq "<DC-Hostname>" }

Did this answer your question?