Hi
In a Windows Server I've installed a SIEM Collector.
When I try to configure a data source (generic log tail), validate and apply, the service creates a new folder in plugins folder, but there isn't a bookmark file and the data source without this bookmark doesn't report anything
How can I do to create the bookmark?
Thanks
Solved! Go to Solution.
Hi
Finally I created a blank file with .bookmark extension, and it works fine
Thanks
the bookmark file is created automatically by the siem collector. if it's not created under the folder, there might be some permission issue writing files to the folder.
Hi
my user is administrator on this server. Do I need that service start with administrator account or local server?
Regards
SIEM collector should just run under local computer service account. Make sure you use the latest SIEM collector version.
Hi
I've the last version. My problem is that in the same collector, I've one data source with bookmark created and another data source without bookmark
Regards
And the one with without bookmark created is not working? What sort of data source is it?
Hi
They are different data sources types, but I've found the solution yesterday.
If I create an empty file, with .bookmark extension, the data source begins to report events
Regards
Still sounds like a permission issue if SIEM collector can't create the bookmark file...
Hi
Finally I created a blank file with .bookmark extension, and it works fine
Thanks
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA