cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Not bookmark in SIEM Collector

Jump to solution

Hi

In a Windows Server I've installed a SIEM Collector.

When I try to configure a data source (generic log tail), validate and apply, the service creates a new folder in plugins folder, but there isn't a bookmark file and the data source without this bookmark doesn't report anything

How can I do to create the bookmark?

Thanks

1 Solution

Accepted Solutions

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

Finally I created a blank file with .bookmark extension, and it works fine

Thanks

View solution in original post

8 Replies
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

the bookmark file is created automatically by the siem collector. if it's not created under the folder, there might be some permission issue writing files to the folder.

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

my user is administrator on this server. Do I need that service start with administrator account or local server?

Regards

Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

SIEM collector should just run under local computer service account. Make sure you use the latest SIEM collector version.

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

I've the last version. My problem is that in the same collector, I've one data source with bookmark created and another data source without bookmark

Regards

Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 6 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

And the one with without bookmark created is not working? What sort of data source is it?

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

They are different data sources types, but I've found the solution yesterday.

If I create an empty file, with .bookmark extension, the data source begins to report events

Regards

Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 8 of 9

Re: Not bookmark in SIEM Collector

Jump to solution

Still sounds like a permission issue if SIEM collector can't create the bookmark file...

Re: Not bookmark in SIEM Collector

Jump to solution

Hi

Finally I created a blank file with .bookmark extension, and it works fine

Thanks

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community