I want to forward events from ESM but they are not being seen by receiving collector - a virtual machine . What is the best way to trace down the problem?
there is a bug in 9.5.2 for static routes so if you use this verion you should upgrade to 9.6.0 MR4 in this version this issue is fixed.
to trubbleshout this problem you need to go with ssh on the ESM and make a TCPdump on eth0 i think. You can filter by your destination IP that should get the forwarded Events.
We are at the latest release. I am working with support to resolve this but they still have not fixed it.
need to understand the steps of forwarding events from SIEM and its uses.
I'm trying also to forward evnts from a data source in 1 receiver to a secend receiver (in the same ESM )
could you help me?
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
2821 Mission College Blvd.
Santa Clara, CA 95054 USA
Consumer Support | Enterprise Support | McAfee.com
Legal | Privacy | Copyright © 2019 McAfee, LLC