Once an Identity Agent is added to the SMS, the SMS will automatically poll the agent
and will display the User ID to User IP correlation and security login events. With
this data, you can search an IP address to view all historical information. When you
first connect the Identity Agent in the SMS, the SMS will automatically poll the domain
controller to get the last 15 minutes of historical information.
![]() |
NoteWhen the SMS is in FIPS mode, it will not be able to communicate with the Identity
Agent.
|
Polling times
The following table defines the polling times for the security login events and metadata
and diagnostics.
Item | Polling time |
Security login events | Every 4-5 seconds |
Metadata and diagnostics | Every 15 minutes |
![]() |
NoteThese are the default times. You can update the polling settings in the Identity Agent.
|
![]() |
NoteYou can manage the User ID IP Correlation data maintained by the SMS when you perform
Database Maintenance and specify retention parameters for the data. See
Database maintenance.
|
High level SMS and Identity Agent configuration process
There are four steps to configure the Identity Agent in the SMS in order to retrieve
User Id IP correlation.
- Add the Identity Agents.
- Create an Agent Group.
- Select an Identity Agent to be in a group.
- Enable the Agent Group that will be actively used by the SMS to poll the Identity Agent for User ID IP correlation data.