cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
TimoL
Level 7
Report Inappropriate Content
Message 1 of 4

SIEM | ePolicy Orchestrator data source stops gathering events

ePolicy Orchestrator data source stops gathering events

Error log 

tail -f -n 50 /var/log/epo.24

 

Mar 11 14:19:25 L_ERROR 01906|ct_fetch returned* _FAIL at [collector/connector/mssql/ntds.c:209 (tds_exec_reader)]
Mar 11 14:19:25 L_ERROR 01906|tds_exec_reader failed at [collector/connector/mssql/tds_connector.c:194 (tds_connector_exec_query)]
Mar 11 14:19:25 L_ERROR 01906|exec_query failed at [collector/connector/connector.c:165 (connector_exec_query)]
Mar 11 14:19:25 L_ERROR 01906|Failed to execute query at [collector/client/client_wrapper.c:143 (client_wrapper_get_data)]
Mar 11 14:19:25 L_ERROR 01906|An error occurred, sleeping for 5 min(s), 00 sec(s) or 300s before retrying

 

epo SQL Connect test via GUI -> OK

 

The datasource works fine for a long time. now it stops working

 

any ideas?

ESM 10.3.4

3 Replies

Re: SIEM | ePolicy Orchestrator data source stops gathering events

Any resolution to this?

 

/Mikael

V1nce
Level 7
Report Inappropriate Content
Message 3 of 4

Re: SIEM | ePolicy Orchestrator data source stops gathering events

I have the same problem but on a different data source. 

The last logging date was May 10 and when I checked it has this error:

May 10 01:06:04 L_ERROR 20743|cs_send at [collector/connector/mssql/ntds.c:147 (tds_exec_reader)]
May 10 01:06:04 L_ERROR 20743|tds_exec_reader failed at [collector/connector/mssql/tds_connector.c:194 (tds_connector_exec_query)]
May 10 01:06:04 L_ERROR 20743|exec_query failed at [collector/connector/connector.c:165 (connector_exec_query)]
May 10 01:06:04 L_ERROR 20743|cmd == NULL at [collector/connector/mssql/ntds.c:127 (tds_exec_reader)]
May 10 01:06:04 L_ERROR 20743|tds_exec_reader failed at [collector/connector/mssql/tds_connector.c:194 (tds_connector_exec_query)]
May 10 01:06:04 L_ERROR 20743|exec_query failed at [collector/connector/connector.c:165 (connector_exec_query)]
May 10 01:06:04 L_ERROR 20743|failed to lookup bookmark query(s) at [collector/client/client_wrapper.c:86 (client_wrapper_get_data)]
May 10 01:06:04 L_ERROR 20743|An error occurred, sleeping for 5 min(s), 00 sec(s) or 300s before retrying
May 10 01:14:07 L_ERROR 20694|received EOF signal...

vsenthil
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 4

Re: SIEM | ePolicy Orchestrator data source stops gathering events

Hello There,
 
We have noticed this issue before and our rules team has fixed these.
 
Can you please check how old is, /usr/local/ess/gsqlConf/357 file on your ESM?
 
And /etc/NitroGuard/gsql/357 on the receiver?
 
Additionally, I recommend you to perform a rule update in ESM and then check if the issue still exists.
 
ESM Properties ->  Rules Update -> Check Now
 
Once rules have been updated in ESM, check the status of events in ePO
 
Regards,
VS
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community