hello team ,
I am using SIEM collector agent for windows hosts
For some of agents from receivers we cans see all the time that they open and close connection
Jan 16 11:51:02 NPP_c[2423]: NPP -- Closing connection from xx.xx.xx.xx
Jan 16 11:51:02 NPP_c[2423]: Got a connection from client IP addr: xx.xx.xx.xx, id = 24
From debug log of agent following message appear:
MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
Is there anyone aware what if the meaning of following message means ?
what version of siem collector? change logging to diagnostic and see more details
Logs:
134> Jan 10 14:23:42 xyz SIEMCollector INFO 1 ClientWrapper::start Client started
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFManager::GetConnection Activating connection: 1
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFManager::GetConnection Active: 1
<135> Jan 10 14:23:42 xyz SIEMCollector DEBUG 1 MEFClient::Begin connection: 1
<131> Jan 10 14:23:49 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFOpen failed to connect due to: Operation is not supported by the active MEF protocol <@ line #1123>
<135> Jan 10 14:23:49 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Not connected <@ line #875>
<131> Jan 10 14:23:49 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Not connected <@ line #875>
<135> Jan 10 14:23:50 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 782 MSec: Not connected <@ line #875>
<131> Jan 10 14:23:50 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:51 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:51 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:51 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 765 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:51 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:52 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:52 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:53 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 985 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:53 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<135> Jan 10 14:23:53 xyz SIEMCollector DIAG 0 MEFConnection::Connect Verify attempt failed after 0 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:53 xyz SIEMCollector ERROR 0 MEFConnection::Connect MEFVerifyConn failed to verify existing connectivity - attempting to reconnect: Operation is not supported by the active MEF protocol <@ line #881>
<135> Jan 10 14:23:54 xyz SIEMCollector DIAG 0 MEFConnection::Connect (Verify) attempt potentially succeeded after 687 MSec: Operation is not supported by the active MEF protocol <@ line #881>
<131> Jan 10 14:23:54 xyz SIEMCollector ERROR 1 MEFConnection::Connect MEFAllocDataDS failed due to: Data source info conflicts with data version <@ line #1463>
<131> Jan 10 14:23:54 xyz SIEMCollector ERROR 1 ClientWrapper::start Failed to process events; receiver communication timeout reached, sleeping for 2 minutes; Pausing client.
<135> Jan 10 14:23:54 xyz SIEMCollector DEBUG 1 MEFClient::End connection: 1
<135> Jan 10 14:23:54 xyz SIEMCollector DEBUG 1 MEFManager::ReleaseConnection Releasing connection: 1
Agent version => latest possible
looks like there's issue with connectivity between the ERC and SIEM collector. are you using hostID? and does the FW allow MEF port?
Hi,
You can follow the below link for configuration of SIEM collector connectivity from Receiver and SIEM collector agent;
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA