> Source: [sk155652](https://support.checkpoint.com/results/sk/sk155652)

# sk155652 - Windows Server / Domain controller that has Advanced Threat Analytics (ATA) enabled not sending AD Query events

| Property | Value |
|----------|-------|
| Solution ID | sk155652 |
| Date Created | 2019-06-11 |
| Last Modified | 2019-06-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Windows Server / Domain controller that has Advanced Threat Analytics (ATA) enabled not sending AD Query events.

* SmartLog is showing:   

  `
  "Connected domain controller did not send AD Query related events in the last 5 minutes. Refer to sk60501 to make sure the necessary events are audited on the domain."`

* In PDPD.elg there are similiar logs:   

  `"ADLOG::GatheringManager::getDomainControllersStatus: status: x.x.x.x@domain.com (connection state 0) events: 0 `  
  `
  ADLOG::PushQueryStrategy::noEventsWarning: After 300 seconds no events arrived from DC . issuing warning log. this(0xbc944c18) `  
  `
  Type:eFtCstring, Value:Connected domain controller did not send AD Query related events in the last 5 minutes. Refer to sk60501 to make sure the necessary events are audited on the domain controller."`

* Packet capture show that a request is sent to the DC IP but no reply is received.

* Windows Management Instrumentation (WMI) permissions are granted to the admin user as per [sk93938](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93938).

* "Audit Account logon events" and "Audit Logon events" are enabled as per [sk60501](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk60501), but issue persist.

* Audit logs are generated on the DC, but the Security Gateway still does not receive events.

* Test_ad_connectivity (according to [sk100406](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100406)) ends with internal errors:  

  `
  :status (SUCCESS_LDAP) `  
  ` 
  :err_msg ("WMI_UNKNOWN;LDAP_SUCCESS") `  
  ` 
  :ldap_status (LDAP_SUCCESS) `  
  ` 
  :wmi_status (WMI_UNKNOWN) `

## Cause

When Advanced Threat Analytics (ATA) is enabled manually or per upgrade, it modifies the permissions and overrides all the other default values. Permissions granted to services on Windows Server like WMI, will be disabled.

In consequence, AD Query will not be able to use Windows Management Instrumentation (WMI) to query Active Directory Domain Controllers for the Security Event logs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
