cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Level 8
Report Inappropriate Content
Message 1 of 10

Warning Flags in ESM Data Source

Hello,

 

we have create a group (Parent Group) in ESM with 4 Clients,

on the clients we do not see the warning flags (Yellow Flags) but on the parrent group we can see the warrning flags.

maybe someone can let me know why we see the warning flag?

what is the correct way to configure a Parnet group with clients.

thanks in advanced.

Labels (3)
9 Replies
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 10

Re: Warning Flags in ESM Data Source

Hi, first of all

there's a few reasones for yellow flags...   click on the flag.

this will open for you the logs file, try to see for what its all about
paste here we will try to assist.

 

Best Regards👍👍👍

David

Highlighted
Level 8
Report Inappropriate Content
Message 3 of 10

Re: Warning Flags in ESM Data Source

Hello,

When we are creating a parent group we giving fake IP, if this is the reason which IP we need to give to parent group? because withgout IP we cannot create the group. 

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 10

Re: Warning Flags in ESM Data Source

Hi, thats not the reason for the flag 

go over with the mouse on the data source (dont click) what does it say?

then click on the flag and open the log file, try to find the error log regarding that data source or group

what does it say there?

 

Best regards👍👍👍

David

Highlighted
Level 8
Report Inappropriate Content
Message 5 of 10

Re: Warning Flags in ESM Data Source

Hello,

when i pass over the flag it marked - "inactive"

and in the logs i did not find any logs.

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 6 of 10

Re: Warning Flags in ESM Data Source

Hi, ok i'm starting to get the picture.

from what i understand from you the 4 clients are working great and sending logs

but still you see a yeloow flag on the parrent for "inactiv"

so, right! your parrent is not sending any logs. becuose i you mentioned before it's a fake IP.

 

if you want to get rid of the yellow flag

just.... delete the fake IP 

put 1 of your clients or chields as a parrent.

 

Best Regards👍👍👍

David

Highlighted

Re: Warning Flags in ESM Data Source

I do see an issue with using one of the production servers as a parent. What happens if that parent ends up being decomed? It will then go inactive. If you end up deleting the device. It will screw up all of the ELM logging and a hassle.

The reason to do a parent to client/child is to really help with policy making. There should be the ability to make a "dumb" grouping for the receiver. Something that you can implement for future would be beneficial.

Something along the lines, "Windows Servers", "Firewalls", "Linux Devices", etc.
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 8 of 10

Re: Warning Flags in ESM Data Source

Hi, i like your udea

but McAfee as a lot to improve in there SIEM...
the User Experiance is in a thery low level

i see a lot of siple functions in Qradar and Logrythm that i really dont understand why McAfee is not implementing that..

i hope the Managers in McAfee wikk wake uo quick..

 

Best Regards👍👍👍

David

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 9 of 10

Re: Warning Flags in ESM Data Source

This option does exist.  You can create policies which your datasources can belong to.  Datasources from different receivers can be added to a single policy - allowing you to ensure that your policies for all datasources of a particular type are generally consistent no matter where in the physical layout the devices sit.  

https://docs.mcafee.com/bundle/enterprise-security-manager-11.3.x-product-guide/page/GUID-8E8001EB-6...

That said, using a dummy parent is still a useful configuration - typically to assist with the datasource limits per receiver (approximately 2000). 

There is an issue related to the behaviour of idle flags in SIEM 11 for client datasources (reference SIEM-15064) so if you are running SIEM 11 and idle flags on clients are causing you an issue please raise a service request to ask for the latest hotfix.  This issue will be fixed from SIEM 11.4.0 onwards.

 

Highlighted
Level 8
Report Inappropriate Content
Message 10 of 10

Re: Warning Flags in ESM Data Source

Hi,

thanks for the reply, after the upgrade to version 11.3 looks like we are getting new type of events - Idle 

and i can see that even if we create a dummy parent IP, its start presenting the Parent device as sending logs

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community