cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

SIEM device status is failing

Jump to solution

Hi,

We encountered an alert today saying that one of our ERCs is failing and it has red flag on the system tree. Checking the flag details we saw error attached to this post. We then checked the status of the ERC and ELM and both were working fine. Any idea as to why this has happened and recommendations? Thanks 

1 Solution

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: SIEM device status is failing

Jump to solution

Dear customer,

This looks like there is a key issue, I would suggest to rekey both devices ERC and ELM (Device properties/Key Managenment/Key Device).

Once this is done from ERC properties click on Receiver Configuration and then Sync ELM.

Hope this will get the red flag cleared.

Best Regards,

Dj

View solution in original post

4 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: SIEM device status is failing

Jump to solution

Dear customer,

This looks like there is a key issue, I would suggest to rekey both devices ERC and ELM (Device properties/Key Managenment/Key Device).

Once this is done from ERC properties click on Receiver Configuration and then Sync ELM.

Hope this will get the red flag cleared.

Best Regards,

Dj

View solution in original post

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 5

Re: SIEM device status is failing

Jump to solution

Dear Customer,

The error indicates there was communication problem with the ELM/ELS.

This will cause the raw logs not to be sent from the ERC to the ELM.

Please execute the 'Sync ELM'  button in the Receiver Management page in Receiver properties.

After performing Sync ELM, you should be able to ssh from the ERC CLI to the ELM IP address without asking for a password. Normally the Sync ELM should be fix any issues between the ERC & the ELM &and ensure the Send2ELM process is running which is the process responsible for sending raw logs to the ELM.

If you are able to successfully SSH from the ERC to the ELM, the red flag error message will disappear after some time.

In order to  clear the flags you can also click on the red flag on the ESM Physical Display & select the flags to clear and click on clear all.

Regards,

Prashanth B Pillai

McAfee Technical Support

Customer Success Group

Highlighted

Re: SIEM device status is failing

Jump to solution

Hi,

I tried looking for the "Sync ELM" but theres no tab like that on the ERC config or ERC management.

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 5 of 5

Re: SIEM device status is failing

Jump to solution

Please ensure you are logged in as NGCP.  If you are, then the lack of a sync ELM button indicates the device is not configured to log to an ELM - please raise a service request so support can check the configuration as you should not get this error if you are not configured to log to any ELS/ELM.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community