cancel
Showing results for 
Search instead for 
Did you mean: 

Not bookmark in SIEM Collector

Jump to solution

Hi

In a Windows Server I've installed a SIEM Collector.

When I try to configure a data source (generic log tail), validate and apply, the service creates a new folder in plugins folder, but there isn't a bookmark file and the data source without this bookmark doesn't report anything

How can I do to create the bookmark?

Thanks

1 Solution

Accepted Solutions
Highlighted

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

Finally I created a blank file with .bookmark extension, and it works fine

Thanks

8 Replies
Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 2 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

the bookmark file is created automatically by the siem collector. if it's not created under the folder, there might be some permission issue writing files to the folder.

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

my user is administrator on this server. Do I need that service start with administrator account or local server?

Regards

Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 4 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

SIEM collector should just run under local computer service account. Make sure you use the latest SIEM collector version.

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

I've the last version. My problem is that in the same collector, I've one data source with bookmark created and another data source without bookmark

Regards

Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 6 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

And the one with without bookmark created is not working? What sort of data source is it?

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

They are different data sources types, but I've found the solution yesterday.

If I create an empty file, with .bookmark extension, the data source begins to report events

Regards

Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 8 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

Still sounds like a permission issue if SIEM collector can't create the bookmark file...

Highlighted

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

Finally I created a blank file with .bookmark extension, and it works fine

Thanks

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community