cancel
Showing results for 
Search instead for 
Did you mean: 

Mcaffee SIEM collector agent error

hello team ,

I am using  SIEM collector agent for windows hosts

For some of agents from receivers we cans see  all the time  that they open and close connection 

Jan 16 11:51:02  NPP_c[2423]: NPP -- Closing connection from xx.xx.xx.xx
Jan 16 11:51:02  NPP_c[2423]: Got a connection from client IP addr: xx.xx.xx.xx, id = 24

From debug log of agent following message appear:

MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>

 

Is there anyone aware what if the meaning of following  message means ?

 

 

4 Replies

Re: Mcaffee SIEM collector agent error

what version of siem collector? change logging to diagnostic and see more details

Highlighted

Re: Mcaffee SIEM collector agent error

Logs:

134> Jan 10 14:23:42 xyz SIEMCollector INFO 1 ClientWrapper::start Client started
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFManager::GetConnection Activating connection: 1
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFManager::GetConnection Active: 1
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFClient::Begin connection: 1
<131> Jan 10 14:23:49 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFOpen failed to connect due to: Operation is not supported by the active MEF protocol <@ line #1123>
<135> Jan 10 14:23:49 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Not connected <@ line #875>
<131> Jan 10 14:23:49 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Not connected <@ line #875>
<135> Jan 10 14:23:50 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 782 MSec: Not connected <@ line #875>
<131> Jan 10 14:23:50 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:51 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:51 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:51 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 765 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:51 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:52 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:52 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:53 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 985 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:53 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:53 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:53 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:54 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 687 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:54 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<131> Jan 10 14:23:54 xyz SIEMCollector ERROR 1 ClientWrapper::start Failed to process events; receiver communication timeout reached, sleeping for 2 minutes; Pausing client.
<135> Jan 10 14:23:54 xyz SIEMCollector DEBUG 1 MEFClient::End connection: 1
<135> Jan 10 14:23:54 xyz SIEMCollector DEBUG 1 MEFManager::ReleaseConnection Releasing connection: 1

Agent version => latest possible

Re: Mcaffee SIEM collector agent error

looks like there's issue with connectivity between the ERC and SIEM collector. are you using hostID? and does the FW allow MEF port?

amarati McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 5 of 5

Re: Mcaffee SIEM collector agent error

Hi, 

You can follow the below link for configuration of SIEM collector connectivity from Receiver and SIEM collector agent;

https://docs.mcafee.com/bundle/siem-collector-11.1.0-install-guide/page/GUID-62864520-DEE4-4F0C-B5F7...

AM_SIEM
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community