For the complete documentation index, see llms.txt. This page is also available as Markdown.

Troubleshooting

This page helps diagnose the most common issues related to user detection, user assignments, activity, and the data displayed in the details card.

Find the symptom that is closest to the issue you are experiencing, then perform the described actions in the specified order.

Quick diagnostics

Issue
What to check first

The user does not appear in the system

Whether they logged in on the monitored computer and whether eAgent sent the data

The same user appears multiple times

The login, domain, and method used to create the entry

The user data is incomplete

Manual editing is available

The user is assigned to the wrong structure

The current assignment in the table or user card

Not all users are visible in the table

The search field, active filters, and visible columns

The user is not visible as logged in

The computer status, eAgent operation, and data freshness

The user is still visible as logged in

The date of the computer's last connection and session termination

Activity information is missing

The monitoring configuration, time range, and computer connection

The user card is empty

User relationships, device data, and active features

The user cannot be edited or deleted

The account permissions and availability of the selected operation

User import does not work

Whether the feature has already been made available in the system

User detection and adding

The user does not appear in the system

A user can be created manually or detected after logging in to a computer monitored by eAgent.

Possible causes

  • the user has not yet logged in on the monitored computer,

  • the computer has not sent current data,

  • eAgent is not running or is not communicating with eAuditor Cloud,

  • the computer is turned off or has the status Offline,

  • the login information has not yet been processed,

  • active filters are hiding the user,

  • the user is using a different login than expected.

Solution

  1. Clear the search field and active filters.

  2. Check whether the user's computer is visible in eAuditor Cloud.

  3. Verify the computer status and the date of its last connection.

  4. Make sure that eAgent is running on the device.

  5. Check whether the user has logged in to Windows.

  6. Wait for the new data to be sent and refresh the table.

  7. Search for the user by login as well, not only by first and last name.

  8. If the user is still not visible, add them manually.

Creating an account in Windows, a domain, or Microsoft Entra ID does not necessarily cause the user to appear immediately in eAuditor Cloud. Automatic detection is based on data sent from the monitored computer.

The same user appears multiple times

Separate entries may apply to:

  • a local and domain account,

  • different domains,

  • a changed login,

  • a manually added entry and an automatically detected entry,

Solution

  1. Compare the logins visible for both entries.

  2. Check the domain and the computers associated with the user.

  3. Open both details cards.

  4. Compare the assigned devices, organizational structure, and recent activity.

  5. Determine which entry is current.

  6. Move the required assignments to the correct user.

  7. Delete the outdated entry only after checking its associations.

The user data is incomplete or incorrect

The scope of automatically detected data depends on the information available on the computer. The system may recognize the login but not receive the first name, last name, position, or organizational structure.

Solution

  1. Open the view Users.

  2. Find the correct entry.

  3. Select action Edit.

  4. Complete or correct the available information.

  5. Save the changes.

  6. Open the user card and check whether the data has been updated.

Data such as position, tags, or organizational structure must be completed manually. eAgent cannot always read them from the operating system.

User import from a file or Microsoft Entra ID is not available

Import from a file and Microsoft Entra ID is a planned feature. If the appropriate option is not visible or active, it means that it has not yet been made available in the version of the system you are using.

Until it is deployed, users can be:

  • automatically detected by eAgent,

  • added manually.

Information about the availability of import will appear in the system change log.

Logins and computer associations

The user is not visible as logged in on the computer

Possible causes

  • the computer has not yet sent current data,

  • the device has the status Offline,

  • eAgent is not running,

  • the user has ended the session,

  • the login information has not yet been updated,

  • the user is logging in with a different account.

Solution

  1. Check the computer status.

  2. Verify the date of the device's last connection.

  3. Make sure that eAgent is running.

  4. Check the local login of the currently logged-in person.

  5. Compare it with the login visible in eAuditor Cloud.

  6. Refresh the data after the computer reconnects.

The user is still visible as logged in after finishing work

The information may come from the most recent data sent by the computer. If the device was turned off or lost connection before session termination information was transmitted, the status may remain outdated.

Solution

  1. Check the user's last activity date.

  2. Verify the computer's last connection date.

  3. Check whether the device has the status Online.

  4. Wait for the device to reconnect and send the data again.

  5. Refresh the user card.

  6. If the status still does not change, check whether eAgent is running on the computer.

The user is visible as logged in on several computers

This does not necessarily indicate an error. The user may have active sessions on several devices or be using a remote connection.

It is also possible that one of the computers has not yet sent session termination information.

Solution

  1. Open the user card.

  2. Check the list of computers in the section Currently in use.

  3. Compare the session start time and the last activity time.

  4. Check the status and last connection of each device.

  5. Verify whether the user was using a remote connection.

  6. If the entry is outdated, wait for the computer to reconnect.

How does an assigned computer differ from a currently used computer?
  • Assigned computer - the device for which the user has been indicated as the owner.

  • Currently used computer - the device on which a user session or activity was detected.

A user may be assigned to one computer while also logging in on other devices. Therefore, both lists do not have to contain the same entries.

Assignments and organizational structure

The user is assigned to the wrong structure

Solution

  1. Go to the view Users.

  2. Select the correct user.

  3. Open the menu of available actions.

  4. Select assignment to the organizational structure.

  5. Specify the correct department, branch, or location.

  6. Confirm the operation.

  7. Open the user card and check the new assignment.

If the change is not visible immediately, refresh the page and reopen the user card.

The user cannot be assigned to a structure

Possible causes

  • the organizational structure has not yet been created,

  • the user does not have permission to perform the operation,

  • the user has not been selected in the table,

  • the user entry has been changed or deleted,

  • the page displays outdated data.

Solution

  1. Check whether the correct unit exists in the organization configuration.

  2. Refresh the view Users.

  3. Select the correct entry again.

  4. Check your account permissions.

  5. Select the structure and confirm the operation.

  6. If the issue persists, log out and log in again.

The assigned user is not the owner of the device

Assigning a user to an organizational structure does not automatically assign them as the owner of a computer or other device.

To specify the device owner:

  1. Open the detailed card of the computer or device.

  2. Go to the tab Overview or Users.

  3. In the section Owner select Edit.

  4. Specify the correct user.

  5. Save the change.

User activity

There is no activity data in the user card

Possible causes

  • the appropriate monitoring scheme has not been configured,

  • the scheme has not been assigned to the computer,

  • the computer has not yet sent data,

  • eAgent is not running or the device is Offline,

  • an incorrect time range was selected,

  • the user was not active during the selected period,

  • the given feature is not available in the active plan.

Solution

  1. Check the status of the user's computer.

  2. Verify the date of the last connection.

  3. Make sure that the appropriate monitoring scheme is configured.

  4. Check whether the scheme has been assigned to the correct computer.

  5. Change the time range in the tab Activity.

  6. Clear the active filters.

  7. Wait for the new data to be sent.

Activity monitoring does not work retroactively. Data will be collected from the moment the appropriate scheme is configured and assigned.

The visited page was assigned to the user, even though they did not open it

The domain may be triggered in the background by:

  • an ad,

  • a script,

  • a redirect,

  • a background application,

  • an embedded element on another page,

  • a system service or browser extension.

Before drawing conclusions, check:

  1. the time and number of connections,

  2. the computer from which the entry originated,

  3. the category and risk level of the page,

  4. the user's activity at the same time,

  5. whether the domain was part of another visited website.

Activity data is outdated

Solution

  1. Check the selected time range.

  2. Refresh the user card.

  3. Verify the computer status and the date of the last connection.

  4. Check eAgent operation.

  5. Make sure that the monitoring scheme is still active.

  6. Wait for the next batch of data to be sent.

User card, alerts, and documents

The user card does not contain the expected information

The card displays only data collected by the system and information entered or assigned by the administrator.

Solution

  1. Check whether the correct user was opened.

  2. Compare the login and account name.

  3. Verify the assigned computers and devices.

  4. Check the date of the last activity.

  5. Open the correct tab:

    • Overview,

    • Details,

    • Activity,

    • Alerts,

    • Documents.

  6. Clear the filters and expand the time range.

  7. Check the monitoring configuration.

The document cannot be added or removed

Possible causes

  • the user does not have sufficient permissions,

  • the file exceeds the supported size,

  • the file format is not supported,

  • the file name contains invalid characters,

  • the document is in use or has already been deleted,

  • a connection problem occurred.

  • There is no space left in the database.

Solution

  1. Refresh the tab Documents.

  2. Check your account permissions.

  3. Verify the file name, format, and size.

  4. Try adding the document again.

  5. When deleting, check whether the correct file was selected.

  6. Verify your plan and the amount of available database space.

ilość dostępnego miejsca w bazie danych
The amount of available database space.
  1. If the issue persists, save the error message and take a screenshot.

Table, filters, and operations

Not all users are visible in the table

Solution

  1. Clear the main search field.

  2. Remove filters applied in the columns.

  3. Check the selected data range.

  4. Refresh the table.

  5. Check the column visibility settings.

  6. Verify that the user does not appear under a different login.

  7. Check the next pages of the table.

The required column is not visible
  1. Open the column view settings.

ustawienia widoku kolumn
Column view settings.
  1. Find the required item.

  2. Mark it as visible.

  3. If necessary, drag the column to a different position.

  4. Close the settings and check the table.

The user cannot be edited or deleted

Possible causes

  • the user has not been selected,

  • the administrator account does not have the required permissions,

  • the data in the table is outdated,

  • the user entry was changed or deleted earlier.

Solution

  1. Refresh the table.

  2. Select one user.

  3. Reopen the menu of available actions.

  4. Check your account permissions.

  5. Try performing the operation from a single user record.

A deleted user appeared again

If the user logs in again on a monitored computer, the system may detect their account and create the entry again.

Solution

  1. Check the login of the newly detected user again.

  2. Open their card and verify the associated computer.

  3. Determine whether the account is still being used.

  4. If the account should be retired, delete or block it in the source system, for example in Windows or the domain.

  5. Then delete the outdated entry from eAuditor Cloud.

Before submitting a request to Support

Error report

For the request to be analyzed efficiently, it should include all the information required by the procedure below.

Requests should be sent to:

support@eauditor.eu

In the request content, provide:

  • contact details of the person responsible for communication regarding the request,

  • a description of the issue as precise as possible,

  • the name or login of the user affected by the issue,

  • the name of the associated computer,

  • information on whether the issue affects one user or multiple users,

  • the name of the tab where the issue occurs,

  • a description of the actions taken to resolve the issue independently,

  • the date and time the issue occurred,

  • the eAgent status and the date of the computer's last connection,

  • the applied filters and the selected time range,

  • screenshots, error messages, or other materials useful for analysis.

After sending the message to support@eauditor.eu the request will be automatically confirmed with a return message.

If no confirmation is received, the request may not have reached the Support team. In that case, check that the recipient address is correct and send the message again.

Last updated

Was this helpful?