Unsolved
This post is more than 5 years old
1 Rookie
•
84 Posts
0
2466
May 2nd, 2017 21:00
Avtar logon using individual ID to start backup
Hello All,
During Security audit, we found out from the log that some individual user account was used to run avtar.exe on servers that he doesn't even have access to. Does avtar.exe need to use user account to start backup? You can see the details in the attachment.
Any idea?
No Events found!
J_H_
2 Intern
•
498 Posts
0
May 10th, 2017 07:00
how do you have security on Avamar set up
we use LDAP, so we have it for the user name to start the admin console on their workstation
example
I have the console installed on my pc
I start the console
choose the server
me@mydomain.com
my normal password for "me" account (same account I log in with)
I get the console
my account in LDAP config on the Avamar gui says I am an admin.
Now we do not backup any pc. So if you backup pc it might be they are starting the restore gui on the pc?
L82lqvSg1212481
50 Posts
0
May 10th, 2017 15:00
Can you check what user account is the backup agent service is running as on that server?
Aegh
1 Rookie
•
84 Posts
0
May 10th, 2017 19:00
We are using Local System to run backup agent service. We don't have any special service account for backup.
L82lqvSg1212481
50 Posts
0
May 13th, 2017 22:00
If backup agent service is running as local system, which means avtar was not called by backup agent service, it could only be someone run avtar as the logon user on that server.
enwillson2
1 Message
0
June 16th, 2017 09:00
We are having a similar issue - just wondering if anyone else is experiencing this..... or maybe someone from EMC could comment.
It appears that as the scheduled backup beigins there are logins from multiple users at the same time (down to the second) that are potentially called by Avamar.
brunoparl
5 Posts
0
October 12th, 2017 05:00
there is a KB from EMC where this problem is discribed...I will contact the support and will update this post
https://support.emc.com/kb/501160
brunoparl
5 Posts
0
October 13th, 2017 05:00
here the response from emc that worked for me