we have ESM version 11.3, we started to seen events shown as Unknown_0 instaed parsed events in the ESM.
just wanted to know if someone else had this issue and solve it?
Solved! Go to Solution.
Depending on what patch level you have (anything from HF8 or later for 11.3.0) there is a new process running on the ESM that helps with several things called NSYNC. If NSYNC isn't running it can cause events to show up with the Unknown_0 description.
SSH to the ESM and try running "service nsync start" and give the system a bit of time to fill in the event named.
If that doesn't work or your on patch 7 or earlier, I'd go ahead and log a support ticket since the root cause may actually be on the Receiver and require manual intervention from support on its' database.
Suddenly observing unknown_0 as rule message and all ASP rules were disabled. Can anyone please help with this. Hotfix 13 is already applied. nsync service restarted too.
We found the unknown_0 events in McAfee ESM 11.3.2 HF 3. We have done service restart for nsync in Management and Replica ESM.
Post restart also we could see the Unknonw_0 events from the same Receiver.
Do we have any fix / work around or is it expected in 11.3.2 HF 3?
Unknown_0 indicates that the event description hasn’t made it from the receiver to the ESM. It could be that it wasn’t created in the first place or that it is old and so the ESM is not aware that it needs to download it.
The steps to work out what’s going on are: