Hello,
we have create a group (Parent Group) in ESM with 4 Clients,
on the clients we do not see the warning flags (Yellow Flags) but on the parrent group we can see the warrning flags.
maybe someone can let me know why we see the warning flag?
what is the correct way to configure a Parnet group with clients.
thanks in advanced.
Solved! Go to Solution.
Hi,
thanks for the reply, after the upgrade to version 11.3 looks like we are getting new type of events - Idle
and i can see that even if we create a dummy parent IP, its start presenting the Parent device as sending logs
Hi, first of all
there's a few reasones for yellow flags... click on the flag.
this will open for you the logs file, try to see for what its all about
paste here we will try to assist.
Best Regards👍👍👍
David
Hello,
When we are creating a parent group we giving fake IP, if this is the reason which IP we need to give to parent group? because withgout IP we cannot create the group.
Hi, thats not the reason for the flag
go over with the mouse on the data source (dont click) what does it say?
then click on the flag and open the log file, try to find the error log regarding that data source or group
what does it say there?
Best regards👍👍👍
David
Hello,
when i pass over the flag it marked - "inactive"
and in the logs i did not find any logs.
Hi, ok i'm starting to get the picture.
from what i understand from you the 4 clients are working great and sending logs
but still you see a yeloow flag on the parrent for "inactiv"
so, right! your parrent is not sending any logs. becuose i you mentioned before it's a fake IP.
if you want to get rid of the yellow flag
just.... delete the fake IP
put 1 of your clients or chields as a parrent.
Best Regards👍👍👍
David
Hi, i like your udea
but McAfee as a lot to improve in there SIEM...
the User Experiance is in a thery low level
i see a lot of siple functions in Qradar and Logrythm that i really dont understand why McAfee is not implementing that..
i hope the Managers in McAfee wikk wake uo quick..
Best Regards👍👍👍
David
This option does exist. You can create policies which your datasources can belong to. Datasources from different receivers can be added to a single policy - allowing you to ensure that your policies for all datasources of a particular type are generally consistent no matter where in the physical layout the devices sit.
That said, using a dummy parent is still a useful configuration - typically to assist with the datasource limits per receiver (approximately 2000).
There is an issue related to the behaviour of idle flags in SIEM 11 for client datasources (reference SIEM-15064) so if you are running SIEM 11 and idle flags on clients are causing you an issue please raise a service request to ask for the latest hotfix. This issue will be fixed from SIEM 11.4.0 onwards.
Hi,
thanks for the reply, after the upgrade to version 11.3 looks like we are getting new type of events - Idle
and i can see that even if we create a dummy parent IP, its start presenting the Parent device as sending logs
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA