Activity Monitor Bug Fix List

:pushpin: Looking for a bug fix list for all versions of Activity Monitor?
All bug fixes will automatically be added here!

9.0 Updates

Activity Monitor 9.0.1469 Patch Version Released

March 12, 2026

Active Directory

  • Fixed Kerberos activity reporting issues introduced by the 2026‑03 Microsoft updates on Windows Server 2016, 2019 and 2022.

Linux

  • Fixed an issue where file paths were reported incorrectly for activity on SMB shares, causing intermediate folders to be omitted and resulting in shortened, inaccurate paths in activity reports. (Case 00445751)

API Server

  • Fixed an issue where requesting an API authentication token immediately after registering a new API client could fail with an ā€œunknown client IDā€ error, requiring a delay before the new credentials were recognized.

Included Module Versions

  • Active Directory Module - 7.5.0.287

Netwrix Activity Monitor Patch Version 9.0.1456 Released

February 12, 2026

Active Directory

Fixed LDAP Search and LDAP Bind activity reporting issues introduced by the 2026‑02 Microsoft updates on Windows Server 2019 and 2022.

Included Module Versions

  • Active Directory Module - 7.5.0.274

Patch Version 9.0.1453 Released

January 27, 2026

NetApp

  • Fixed an issue where monitoring sometimes failed to recover after the agent server reboot (Case 00462512)

Included Module Versions

  • Active Directory Module - 7.5.0.272

Patch Version 9.0.1449 Released

January 15, 2026

Active Directory

  • Fixed Kerberos activity reporting issues introduced by the 2026‑01 Microsoft updates on Windows Server 2016, 2019, 2022 and 2025.
  • Fixed a potential LSASS crash on Windows Server 2025 systems.
  • Reduced CPU utilization by optimizing objectClass resolution.

Console

  • Fixed a potential crash during the search.

Patch Version 9.0.1434 Released

November 25, 2025

Active Directory

  • Fixed a potential LSASS crash on Windows Server 2025 systems with the KB5068861 (2025-11) update installed.

Azure Files

  • Resolved an issue where Attribute Change events were not reported.

SQL Server

  • Increased default Extended Events session parameters (max file size, rollover files, and max memory) to improve handling of high-load configurations (Case 00454694).
Included module versions
  • Active Directory Module — 7.5.0.256

Netwrix Activity Monitor Version 9.0 Released

November 13, 2025

No bugs were fixed in this update.

8.0 Updates

Activity Monitor Patch Version 8.0.352 Released

March 12, 2026

Active Directory

Fixed Kerberos activity reporting issues introduced by the 2026‑03 Microsoft updates on Windows Server 2016, 2019 and 2022.

Included Module Versions

  • Active Directory Module - 7.4.0.293

Netwrix Activity Monitor Patch Version 8.0.351 Released

March 5, 2026

Netapp

  • Added support for monitoring multiple FPolicy policies with the Enable and Connect feature, allowing you to specify more than one policy name (e.g., one for CIFS and another for NFS) so that all listed policies are properly enabled and reconnected (Case 00467162).

Included Module Versions

  • Active Directory Module - 7.4.0.291

Netwrix Activity Monitor Patch Version 8.0.346 Released

February 12, 2026

Active Directory

Fixed LDAP Search and LDAP Bind activity reporting issues introduced by the 2026‑02 Microsoft updates on Windows Server 2019 and 2022.

Included Module Versions

  • Active Directory Module - 7.4.0.291

Minor Version 8.0.345 Released

January 27, 2026

NetApp

Fixed an issue where monitoring sometimes failed to recover after the agent server reboot (Case 00462512)

Inactivity Alerts

Fixed an issue where alerts sometimes failed to notify about inactive hosts after an agent server reboot (Case 00462512)

Included Module Versions

  • Active Directory Module - 7.4.0.289

Patch Version 8.0.343 Released

January 15, 2026

Active Directory

Fixed Kerberos activity reporting issues introduced by the 2026‑01 Microsoft updates on Windows Server 2016, 2019, 2022 and 2025.

Included Module Versions

  • Active Directory Module - 7.4.0.289

Patch Version 8.0.331 Released

November 25, 2025

Active Directory

  • Fixed a potential crash of LSASS that may occur on Windows Server 2025 with the KB5068861 (2025-11) update installed.

Linux

  • Fixed an issue where monitoring failed if the agent ran under a service account without a corresponding group of the same name.

SharePoint

  • Fixed an issue where large events could block subsequent event transmission via UDP syslog

Security

  • Updated outdated software dependencies.
Included module versions
  • Active Directory Module — 7.4.0.282

Netwrix Activity Monitor Version 8.0.316 Released

November 13, 2025

No bugs were fixed in this update.

Patch Version 8.0.315 Released

November 6, 2025

  • Console — Fixed an issue where no agents were displayed after upgrading to the latest 8.0 update (Case 00458548).
  • Entra ID — Added support for Non-interactive User, Service Principal and Managed Identity sign-in event types (Case 00448826).
  • Active Directory — Fixed an issue where Access Analyzer failed to process NTLM logon events of the TicketLogonInformation type with Unable to cast object of type 'System.Int64' to type 'System.String' error. Update for Access Analyzer will be released separately (Case 00454261).

Included Module Versions

  • Active Directory Module — 7.4.0.269

Patch Version 8.0.307 Released

October 17, 2025

Linux

Resolved an issue with incorrect file paths for Samba activity when the Samba share was backed by NFS-mounted storage.

NetApp

Resolved an issue where the product reported the The specified server <IP-address> is already connected error (Cases 00458548, 00453733).

Active Directory

Fixed Kerberos activity reporting issues introduced by the 2025‑10 Microsoft updates.

Included Module Versions

  • Active Directory Module - 7.4.0.269

Patch Version 8.0.288 Released

September 23, 2025

  • NetApp — Fixed a memory leak in the NetApp monitoring service introduced in 8.0.275 (Case 00445343).
  • Active Directory — Fixed an issue where the Install button remained disabled after selecting a new installation package via Update Installer (Case 00455095).
  • SQL Server — Fixed an issue where Extended Events options selected in the Console were not applied to the SQL Server session (Case 00454694).

Included Module Versions

  • Active Directory Module — 7.4.0.250

Patch Version 8.0.275 Released

August 21, 2025

NetApp
Resolved an issue where the Logging Service could stop running, which previously caused the NetApp Monitoring Service to continue event collection without reporting, leading to memory exhaustion. With this update, the Monitoring Service now detects when the Logging Service is down, restarts it automatically, and re-establishes event forwarding. Additional diagnostic logging has been added to assist with future troubleshooting.

Included Module Versions

  • Active Directory Module - 7.4.0.233

Patch Version 8.0.272 Released

August 14, 2025

Active Directory

  • Updated AD module now supports the August 2025 Microsoft KBs previously noted in our August 12 announcement.

SharePoint Online

  • Resolved an issue where file information was missing from FileRecycled events generated by SharePoint system processes.
  • Fixed missing access rights in CompanyLinkCreated sharing events.
  • Addressed parsing issues related to access levels in Sharing events.
  • Added support for filtering events by Client App during monitoring and search.
  • Improved search experience by enhancing visibility of target account display names, client apps, clarifying Event Data descriptions, and displaying list names instead of internal IDs for group names.

CTERA

  • Fixed an issue where only a Permission Change event was logged when file attributes and permissions changed simultaneously.
Included Module Versions
  • Active Directory Module – 7.4.0.233

Patch Version 8.0.253 Released

July 29, 2025

Nasuni

  • Improved AMQP Connection Stability:

    • Issue: Occasional slow DNS responses during AMQP setup caused delays that sometimes led to agent disconnections.
    • Fix: This hotfix removes the DNS dependency from the negotiation process, improving connection stability and reducing the likelihood of timeouts or drops.

Included Module Versions

  • Active Directory Module - 7.4.0.227

Patch Version 8.0.243 Released

July 3, 2025

Nasuni

  • Resolved a compatibility issue with Nasuni version 9.5 that was introduced in the previous update, 8.0.236. This update supports both Nasuni 9.5 and Nasuni 10.

Search

  • Improved archive search performance by excluding files outside the specified time interval.

Included Module Versions

  • Active Directory Module – 7.4.0.221

Patch Version 8.0.237 Released

June 12, 2025

This patch addresses several critical issues and improvements.

  • Microsoft KB Compatibility (June 2025): Restored Active Directory monitoring capabilities that were impacted by Microsoft’s June 10, 2025 Patch Tuesday updates, as detailed in this community post.
  • Nasuni Compatability: Resolved a certificate trust issue that was preventing event collection for organizations using Nasuni version 10.

Included Module Versions

  • Active Directory Module - 7.4.0.219

Patch Version 8.0.224 Released

June 5, 2025

NetApp
  • Fixed an issue where the ā€œSuppress duplicate operations for N secondsā€ setting did not apply to Read events. The agent continued to use the default 60-second interval regardless of the configured value.
  • Fixed an issue where the FPolicy Scope was unnecessarily updated even when no configuration changes were made.
Syslog
  • Corrected an issue where Syslog outputs mistakenly included the STEALTHAUDIT=ON attribute (intended for Access Analyzer log files). This attribute is now correctly applied only to Log File outputs.
Nasuni
  • The Console now correctly reports the 500 Internal Error from API calls to Nasuni Edge Appliance 10.0 when retrieving server information. Previously, it incorrectly displayed: ā€œHttps: Custom certificate is invalid. One or more errors occurred.ā€
CTERA
  • Fixed an issue where ā€˜Attribute Change’ events were reported with empty changes, even when no attributes were modified.
  • Resolved an issue where debug logs displayed ā€œFailed to parse messageā€ errors during operations involving extended attributes.
  • Fixed an issue where the %ORIGINATING_SERVER% Syslog macro did not report the Edge Filer name as expected.
Windows
  • Resolved an issue where an extra Read event was sometimes logged immediately after a file was deleted.
Entra ID
  • Addressed a bug where the User Principal Name (UPN) was occasionally reported as the username in certain Sign-In events.
Console
  • The Console now prompts users to subscribe to Netwrix Community to receive important update notifications.

Included Module Versions

  • Active Directory Module - 7.4.0.201

Patch Version 8.0.208 Released

May 15, 2025

Active Directory. Microsoft KB May 13, 2025 Update

On May 13th, 2025, Microsoft distributed KB’s which conflict with existing AD Module used in Netwrix Activity Monitor for AD. If these KB’s are applied to your systems, they will conflict with current AD module as described below.

• Functional:
ā—‹ Server 2025 - KB5058411
– AD module will lose the ability to capture NTLM Authentication events (Termsrv (JumpBox)
ā—‹ Expected ADMonitor_Logs Error:

  • Couldn’t resolve NlpLogonSamLogon for Windows Server 2022 (20348.2400)
  • Couldn’t resolve NlpUserValidate
  • Couldn’t resolve CConnectionEx::InitializeClientData (4 param)

ā—‹ Server 2022 - KB5058385
– AD module will lose the ability to capture Kerberos and NTLM Authentication events
ā—‹ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest
  • Couldn’t resolve I_GetASTicket
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpUserValidate (Old)
    - Couldn’t resolve NlpUserValidate

ā—‹ Server 2019 - KB5058392
– AD module will lose the ability to capture or block Kerberos and NTLM Authentication events
ā—‹ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest
  • Couldn’t resolve I_GetASTicket
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpUserValidate (Old)
  • Couldn’t resolve NlpUserValidate

ā—‹ Server 2016 - KB5058383
– AD module will lose the ability to capture Kerberos and NTLM Authentication events
ā—‹ Expected ADMonitor_Logs Error:

  • Couldn’t resolve HandleTGSRequest
  • Couldn’t resolve I_GetASTicket
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpLogonSamLogon
  • Couldn’t resolve NlpUserValidate (Old)
  • Couldn’t resolve NlpUserValidate

• Stability:
ā—‹ No stability impact on any server platforms / Domain Controllers

File activity on RHEL 9

The product failed to collect file system events on some Red Hat Enterprise Linux 9 servers due to a failure to register the monitoring service process.

Included Module Versions

  • Windows Driver - 1.25.507.1302
  • Active Directory Module - 7.4.0.201

Patch Version 8.0.190 Released

May 8, 2025

  • Resolved an issue where adding new Entra ID, SharePoint Online, or Exchange Online services did not retain configuration settings.
    All entered filters and options are now properly saved, and the Open Instruction button is functional without requiring a post-setup edit.

  • Improved compatibility with Dell CEE 9.0.1+ by automatically correcting invalid configurations.
    When HTTP and HTTPS are both disabled, Activity Monitor now enables HTTP if Dell appliances are detected. It also disables the Access List if no IPs are explicitly allowed — ensuring seamless monitoring without manual registry edits.

    :information_source: Note: Dell CEE 9.0.1 introduced two new security settings that may block event collection by default:
    – Enable HTTP Server (disabled by default)
    – Enable AccessList (enabled by default, requires manual IP allow-listing)

    These settings affect monitoring of Dell Isilon/PowerScale, Unity, and PowerStore appliances.

Included Module Versions

  • Netwrix Activity Monitor – 8.0.190
  • SBTService – 1.25.404.1430
  • Active Directory Module – 7.4.0.180

Patch Version 8.0.171 Released

May 1, 2025

Fix: Dell CEE Now Properly Duplicates Events to Secondary Agents

Issue Summary:
Previously, an agent misconfiguration caused events to be delivered only to the local agent.

Behavior Before:
A misconfigured agent modified the EndPoint parameter in the CEE configuration, excluding other agents from receiving events.

Behavior After:
The agent now correctly retains all configured addresses in the EndPoint parameter, ensuring that events are duplicated to all intended agents.


Included Module Versions

  • Netwrix Activity Monitor: 8.0.171
  • SBTService: 1.25.404.1430
  • Active Directory Module: 7.4.0.180

Patch Versions 8.0.162 Released

April 10, 2025

Active Directory

Affected System(s):
  • Windows Server 2022 (for Active Directory)
  • Windows Server 2019 (for Active Directory)
  • Windows Server 2016 (for Active Directory)
Affected Platform/KB:
  • Windows Server 2022 KB5055526
  • Windows Server 2019 KB5055519
  • Windows Server 2016 KB5055521
Impact:
Functional:
  • Server 2022 - KB5055526 Netwrix AD module will lose the ability to capture LDAP Bind events and the ability to capture FSMO role change events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest
    • Couldn’t resolve DsaGetValidFSMOs
  • Server 2019 - KB5055519 Netwrix AD module will lose the ability to capture Kerberos Authentication events and the ability to capture LDAP Bind events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest
    • Couldn’t resolve HandleTGSRequest
  • Server 2016 - KB5055521 Netwrix AD Module will lose the ability to capture LDAP Bind events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest

Other changes

  • Connection test failure for NetApp hosts
    The Connect button for NetApp hosts failed with ā€œAn item with the same key has already been addedā€ error when the host had more than one output. The problem did not affect monitoring.

Version 8.0.162 Includes:

  • Netwrix Activity Monitor - 8.0.162
  • SBTService - 1.25.331.1110
  • Active Directory Module - 7.4.0.180

Patch Version 8.0.156 Released

April 8, 2025

SharePoint Online

  • SharePoint Online audit data collection, which previously failed with a ā€œCannot get information about the root SharePoint siteā€ error when using an HTTP proxy, now works successfully with or without a proxy.

REST API

  • PATCH requests to modify NetApp hosts, which previously failed with a 404 error when the host was monitored by multiple agents, now work as expected regardless of the number of monitoring agents.

Patch Version 8.0.142 Released

March 18, 2025

  • Qumulo monitoring service

    • File system event processing has been updated to efficiently handle Qumulo-specific activity patterns both with and without the MS Office filtering. Office filtering has been optimized across all file systems. Temp file filtering has been moved from Path Filters to a more efficient internal process.
  • 2025 Server - KB5053598

    • Kerberos events will be lost or incomplete.
    • Cases with jump-boxes will no longer be handled correctly
    • Logs:
      ļ‚§ Couldn’t resolve I_GetASTicket
      ļ‚§ Couldn’t resolve CConnectionEx::InitializeClientData (4 param)
  • 2022 Server - KB5053603

    • LDAP Bind and Kerberos events will be lost or incomplete
    • Logs:
      ļ‚§ Couldn’t resolve LDAP_CONN::BindRequest
      ļ‚§ Couldn’t resolve HandleTGSRequest
      ļ‚§ Couldn’t resolve I_GetASTicket
  • 2019 Server - KB5053596

    • LDAP Bind and Kerberos events will be lost or incomplete
    • Logs:
      ļ‚§ Couldn’t resolve LDAP_CONN::BindRequest
      ļ‚§ Couldn’t resolve I_GetASTicket
  • 2016 Server - KB5053594

    • No impact
  • 2012R2 Server - KB5053887

    • Logs: Couldn’t resolve LDAP_CONN::BindRequest

:double_exclamation_mark: The following versions are no longer supported.

7.4 Updates

Patch Version 8.0.278 Released

September 16, 2025

Active Directory

Windows

  • Fixed an intermittent crash of the Windows Monitoring Service that occurred when its configuration was changed.

REST API
Fixed a problem that prevented log files enumeration via the /api/v1/logs/{outputId} endpoint.

Included Module Versions
  • Active Directory Module - 7.4.0.246

Patch Version 8.0.250 Released

July 17, 2025

Active Directory

  • Updated AD module now supports the July 2025 Microsoft KBs previously noted in our July 8 announcement.
  • TGT events are not being sent for existing and non-existing users during the gold ticket attack.
  • Added support for Netwrix Threat Prevention 7.5 agents.

CTERA

  • Improved duplicate suppression of Add, Delete, and Failed Add events.
  • Resolved a problem with the bulk editing of the Portal Filter.

NetApp.

  • Resolved an issue where the automatic configuration of FPolicy over the NetApp REST API failed with the error ā€˜ā€œevents.nameā€ is a required field’.

7.3 Updates

Patch Version 7.1.287 Released

September 16, 2025

Active Directory

  • Updated AD module now supports the August 2025 Microsoft KBs previously noted in our September 9 announcement.
  • Fixed an issue that prevented connections to Netwrix Threat Manager.

Search

Improved archive search performance by excluding files outside the specified time interval.

Windows

Fixed an intermittent crash of the Windows Monitoring Service that occurred when its configuration was changed.

Included Module Versions
  • Active Directory Module - 7.3.9.317

Patch Version 7.1.276 Released

July 17, 2025

Active Directory

  • Updated AD module now supports the July 2025 Microsoft KBs previously noted in our July 8 announcement.
  • TGT events are not being sent for existing and non-existing users during the gold ticket attack.

Included Module Versions

  • Active Directory Module - 7.3.9.303

7.1 Updates

Netwrix Activity Monitor Version 7.1.303 Released

November 13, 2025

No bugs were fixed in this update.

Patch Version 7.1.300 Released

October 17, 2025

Active Directory

Included Module Versions

  • Active Directory Module - 7.3.9.325

Patch Version 7.1.296 Released

September 23, 2025

  • NetApp — Fixed a memory leak in the NetApp monitoring service introduced in 7.1.280 (Case 00445343).
  • Active Directory — Fixed an issue where the Install button remained disabled after selecting a new installation package via Update Installer (Case 00455095).

Included Module Versions

  • Active Directory Module — 7.3.9.317

Patch Version 7.1.280 Released

August 7, 2025

NetApp
Resolved an issue where the Logging Service could stop running, which previously caused the NetApp Monitoring Service to continue event collection without reporting, leading to memory exhaustion. With this update, the Monitoring Service now detects when the Logging Service is down, restarts it automatically, and re-establishes event forwarding. Additional diagnostic logging has been added to assist with future troubleshooting.

Included Module Versions
  • Active Directory Module – 7.3.9.305

Patch Version 7.1.274 Released

June 12, 2025

This patch addresses several critical issues and improvements.

  • Microsoft KB Compatibility (June 2025): Restored Active Directory monitoring capabilities that were impacted by Microsoft’s June 10, 2025 Patch Tuesday updates, as detailed in this community post.
  • Nasuni Compatability: Resolved a certificate trust issue that was preventing event collection for organizations using Nasuni version 10.

Included Module Versions

  • Active Directory Module - 7.3.9.297

Patch Version 7.1.272 Released

June 5, 2025

NetApp
  • Fixed an issue where the ā€œSuppress duplicate operations for N secondsā€ setting did not apply to Read events. The agent continued to use the default 60-second interval regardless of the configured value.
Syslog
  • Corrected an issue where Syslog outputs mistakenly included the STEALTHAUDIT=ON attribute (intended for Access Analyzer log files). This attribute is now correctly applied only to Log File outputs.
Windows
  • Resolved an issue where an additional Read event was sometimes logged immediately after a file deletion.
Entra ID
  • Addressed a bug where the User Principal Name (UPN) was occasionally reported as the username in certain Sign-In events.

Included Module Versions

  • Active Directory Module - 7.3.9.286

Patch Version 7.1.267 Released

April 10, 2025

Active Directory

Affected System(s):
  • Windows Server 2022 (for Active Directory)
  • Windows Server 2019 (for Active Directory)
  • Windows Server 2016 (for Active Directory)
Affected Platform/KB:
  • Windows Server 2022 KB5055526
  • Windows Server 2019 KB5055519
  • Windows Server 2016 KB5055521
Impact:
Functional:
  • Server 2022 - KB5055526 Netwrix AD module will lose the ability to capture LDAP Bind events and the ability to capture FSMO role change events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest
    • Couldn’t resolve DsaGetValidFSMOs
  • Server 2019 - KB5055519 Netwrix AD module will lose the ability to capture Kerberos Authentication events and the ability to capture LDAP Bind events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest
    • Couldn’t resolve HandleTGSRequest
  • Server 2016 - KB5055521 Netwrix AD Module will lose the ability to capture LDAP Bind events.
    Expected ADMonitor_Logs Error:
    • Couldn’t resolve LDAP_CONN::BindRequest

Other changes

  • Connection test failure for NetApp hosts
    The Connect button for NetApp hosts failed with ā€œAn item with the same key has already been addedā€ error when the host had more than one output. The problem did not affect monitoring.

Included Module Versions

  • Netwrix Activity Monitor - 7.1.267
  • SBTService - 1.25.331.1110
  • Active Directory Module - 7.3.9.266

Patch Version 7.1.265 Released

March 14, 2025

  • 2025 Server - KB5053598

    • Kerberos events will be lost or incomplete.
    • Cases with jump-boxes will no longer be handled correctly
    • Logs:
      ļ‚§ Couldn’t resolve I_GetASTicket
      ļ‚§ Couldn’t resolve CConnectionEx::InitializeClientData (4 param)
  • 2022 Server - KB5053603

    • LDAP Bind and Kerberos events will be lost or incomplete
    • Logs:
      ļ‚§ Couldn’t resolve LDAP_CONN::BindRequest
      ļ‚§ Couldn’t resolve HandleTGSRequest
      ļ‚§ Couldn’t resolve I_GetASTicket
  • 2019 Server - KB5053596

    • LDAP Bind and Kerberos events will be lost or incomplete
    • Logs:
      ļ‚§ Couldn’t resolve LDAP_CONN::BindRequest
      ļ‚§ Couldn’t resolve I_GetASTicket
    • 2016 Server - KB5053594
    • No impact
  • 2012R2 Server - KB5053887

    • Logs: Couldn’t resolve LDAP_CONN::BindRequest