Size: a a a

MaxPatrol SIEM & VM

2021 May 01

EM

Eugene Matveev in MaxPatrol SIEM & VM
Looks like reciever is down
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
siemserver-receiver.service      loaded active running SIEM Server receiver
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Hm...
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Siem can't process incoming messages
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Try to deploy siem content in PTKB
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Also check address of core rmq in siem.conf
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
What is the path for Siem.conf file?
источник

m

max in MaxPatrol SIEM & VM
/opt/mpxsiem/etc/siem.conf
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Also check disk free space on siem server
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
> 30 Gb
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
yes we have more
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Ok. Now check core rmq address in siem.conf
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
checked it correct
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Wow
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
deeper investigation:
- check consumers in this queue
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
- try to redeploy siem content in PTKB
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
We did will try again
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
For some reason siem reciever can't get messages from core rmq
источник

EM

Eugene Matveev in MaxPatrol SIEM & VM
Show me consumers, please
источник

MH

Mohammed Houssani in MaxPatrol SIEM & VM
источник