we have create a group (Parent Group) in ESM with 4 Clients,
on the clients we do not see the warning flags (Yellow Flags) but on the parrent group we can see the warrning flags.
maybe someone can let me know why we see the warning flag?
what is the correct way to configure a Parnet group with clients.
thanks in advanced.
Hi, first of all
there's a few reasones for yellow flags... click on the flag.
this will open for you the logs file, try to see for what its all about
paste here we will try to assist.
Hi, thats not the reason for the flag
go over with the mouse on the data source (dont click) what does it say?
then click on the flag and open the log file, try to find the error log regarding that data source or group
what does it say there?
Hi, ok i'm starting to get the picture.
from what i understand from you the 4 clients are working great and sending logs
but still you see a yeloow flag on the parrent for "inactiv"
so, right! your parrent is not sending any logs. becuose i you mentioned before it's a fake IP.
if you want to get rid of the yellow flag
just.... delete the fake IP
put 1 of your clients or chields as a parrent.
Hi, i like your udea
but McAfee as a lot to improve in there SIEM...
the User Experiance is in a thery low level
i see a lot of siple functions in Qradar and Logrythm that i really dont understand why McAfee is not implementing that..
i hope the Managers in McAfee wikk wake uo quick..
This option does exist. You can create policies which your datasources can belong to. Datasources from different receivers can be added to a single policy - allowing you to ensure that your policies for all datasources of a particular type are generally consistent no matter where in the physical layout the devices sit.
That said, using a dummy parent is still a useful configuration - typically to assist with the datasource limits per receiver (approximately 2000).
There is an issue related to the behaviour of idle flags in SIEM 11 for client datasources (reference SIEM-15064) so if you are running SIEM 11 and idle flags on clients are causing you an issue please raise a service request to ask for the latest hotfix. This issue will be fixed from SIEM 11.4.0 onwards.
thanks for the reply, after the upgrade to version 11.3 looks like we are getting new type of events - Idle
and i can see that even if we create a dummy parent IP, its start presenting the Parent device as sending logs