The SEC is "online", but there are no events in Security Cloud Control Event Logging Page
Symptom: The Secure Event Connector shows "Active" in Security Cloud Control Secure Connectors page but you do not see events in Security Cloud Control Event viewer.
Solution or workaround:
Procedure
Step 1 | Login to the VM of the on-premise SDC and as the 'sdc' user. At the prompt, type sudo su - sdc. |
Step 2 | Perform these checks:
estreamer-connector RUNNING pid 36, uptime 5:25:17 estreamer-cron RUNNING pid 39, uptime 5:25:17 estreamer-plugin RUNNING pid 37, uptime 5:25:17 estreamer-rsyslog RUNNING pid 38, uptime 5:25:17
firewall-cmd --zone=public --add-port=<udp_port>/udp --permanent firewall-cmd --zone=public --add-port=<tcp_port>/tcp --permanent firewall-cmd --reload
If none of the above repairs work, raise a support ticket with Security Cloud Control support.. |