Hello
I am trying to add ePO to SIEM however the ERC (event receiver) is not present on the newly installed SIEM.
So following advice I am manually trying to add the event receiver. I click the add device button and select "McAfee Event Receiver" and in the following screen, I am putting the IP address of the SIEM server as the IP address Target IP address and I am getting an error message as shown in the screenshot. What could be going wrong here?
Solved! Go to Solution.
I checked with our internal teams and I have been informed the combined appliance is available on the ESM drop-down so you can deploy that if you prefer to have the ESM and Receiver in one appliance:
What do you mean by "the IP address of the SIEM server"?
The ESM should have an IP address
The Receiver must have a different IP address (as it is a separate appliance).
If you wish to deploy a combined appliance you need to download and deploy the combined appliance VM.
Hello Iratcliffe
Thanks for your message. Basically I am trying out the trial version and I am not sure whether its a combined appliance.
I had the 11.3 trial version which had the ERC already but the problem with the 11.3 version is that it uses flash, so I was trying out the 11.4 version and now I am having this issue where I am unable to add the ePO due to it missing the ERC.
Suggestions please 🙂
It looks like we've not released the combined appliance as a trial VM at present. I will ask our product management team about this.
As there is no combined appliance trial VM you need to deploy a Receiver VM as well as the ESM VM.
I checked with our internal teams and I have been informed the combined appliance is available on the ESM drop-down so you can deploy that if you prefer to have the ESM and Receiver in one appliance:
Hello Iratcliffe
Thanks for looking into this. you
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA