cancel
Showing results for 
Search instead for 
Did you mean: 

SIEM Collector 11.x

Ive configured a SIEM collector to send generic log tail, but we are not receiveing any logs in the receiver. we checked the debug log and kept seeing this error over and over:

"<131> Oct 03 15:22:54 localhost SIEMCollector ERROR 0 FileTailBookmarkManager::Init Failed to access logs in directory [D:\AS400]: ERROR [18]"

 

can someone help me to determine the problem? thanks

1 Reply
Highlighted
McAfee Employee mherr
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: SIEM Collector 11.x

Can you provide the configuration you are using?    What is the file name format of the files in the directory?

You can try unc path vs. D:\AS400  such as \\server\d$\AS400\

Also, can you validate the filemask matches the files in the directory?  Can you try *.log if they end in log?

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community