Hi,
We encountered an alert today saying that one of our ERCs is failing and it has red flag on the system tree. Checking the flag details we saw error attached to this post. We then checked the status of the ERC and ELM and both were working fine. Any idea as to why this has happened and recommendations? Thanks
Solved! Go to Solution.
Dear customer,
This looks like there is a key issue, I would suggest to rekey both devices ERC and ELM (Device properties/Key Managenment/Key Device).
Once this is done from ERC properties click on Receiver Configuration and then Sync ELM.
Hope this will get the red flag cleared.
Best Regards,
Dj
Dear customer,
This looks like there is a key issue, I would suggest to rekey both devices ERC and ELM (Device properties/Key Managenment/Key Device).
Once this is done from ERC properties click on Receiver Configuration and then Sync ELM.
Hope this will get the red flag cleared.
Best Regards,
Dj
Dear Customer,
The error indicates there was communication problem with the ELM/ELS.
This will cause the raw logs not to be sent from the ERC to the ELM.
Please execute the 'Sync ELM' button in the Receiver Management page in Receiver properties.
After performing Sync ELM, you should be able to ssh from the ERC CLI to the ELM IP address without asking for a password. Normally the Sync ELM should be fix any issues between the ERC & the ELM &and ensure the Send2ELM process is running which is the process responsible for sending raw logs to the ELM.
If you are able to successfully SSH from the ERC to the ELM, the red flag error message will disappear after some time.
In order to clear the flags you can also click on the red flag on the ESM Physical Display & select the flags to clear and click on clear all.
Regards,
Prashanth B Pillai
McAfee Technical Support
Customer Success Group
Hi,
I tried looking for the "Sync ELM" but theres no tab like that on the ERC config or ERC management.
Please ensure you are logged in as NGCP. If you are, then the lack of a sync ELM button indicates the device is not configured to log to an ELM - please raise a service request so support can check the configuration as you should not get this error if you are not configured to log to any ELS/ELM.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA