To troubleshoot hardware issues on the McAfee SIEM hardware appliance, you need to follow the following steps:
Note: The Linux Diagnostic Tool (LDT) provides a method for checking the status and integrity of any McAfee® Multi Access hardware appliance based on an Intel platform.
Linux Diagnostic tool for McAfee Appliances 2.0.x document provides information about the LDT, including instructions for running diagnostic tools, and for installing the LDT tool on removable media.
I'm want to gather logs from McAfee ESM appliance using the USB method, but the ESM wont boot from the USB. I have installed LDT-getlogs-2.0.6126.img to the flash drive using Linux Live USB Creator, I also installed using sysresccd-installer-2.0.0 for windows, and also wrote the .img file directly to the flash drive, neither of which the USB have started the ESM, how best do I make LDT USB stick that will start the ESM appliance.
You need to change the boot order of the McAfee SIEM to boot from USB, you will be prompted to enter password, which is: MCAFEE