cancel
Showing results for 
Search instead for 
Did you mean: 
kenn1
Level 7
Report Inappropriate Content
Message 1 of 5

Forwarding Events From ESM

I want to forward events from ESM but they are not being seen by receiving collector - a virtual machine . What is the best way to trace down the problem?

4 Replies
xded
Level 12
Report Inappropriate Content
Message 2 of 5

Re: Forwarding Events From ESM

Hi kenn1,

there is a bug in 9.5.2 for static routes so if you use this verion you should upgrade to 9.6.0 MR4 in this version this issue is fixed.

to trubbleshout this problem you need to go with ssh on the ESM and make a TCPdump on eth0 i think. You can filter by your destination IP that should get the forwarded Events.

kenn1
Level 7
Report Inappropriate Content
Message 3 of 5

Re: Forwarding Events From ESM

We are at the latest release. I am working with support to resolve this but they still have not fixed it.

Re: Forwarding Events From ESM

Hello Kenn1,

need to understand the steps of forwarding events from SIEM and its uses.

Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 5 of 5

Re: Forwarding Events From ESM

I'm trying also to forward evnts from a data source in 1 receiver to a secend receiver (in the same ESM )

could you help me?

Thanks'

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator