The SEC is online, but there are no events in Security Cloud Control Firewall Management Event Logging Page
Symptom: The Secure Event Connector shows "Active" in Security Cloud Control Firewall Management Secure Connectors page but you do not see events in Security Cloud Control Firewall Management Event viewer.
Solution or workaround:
Procedure
Step 1 | SSH to your host using the admin account, typically |
Step 2 | Switch to the SDC user with the command |
Step 3 | Perform the following checks:
INFO success: estreamer-connector entered RUNNING state, process has stayed up for > than 1 seconds INFO success: estreamer-plugin entered RUNNING state, process has stayed up for > than 1 seconds INFO success: estreamer-rsyslog entered RUNNING state, process has stayed up for > than 1 seconds
firewall-cmd --zone=public --add-port=<udp_port>/udp --permanent firewall-cmd --zone=public --add-port=<tcp_port>/tcp --permanent firewall-cmd --reload
If none of the above repairs work, raise a support ticket with Security Cloud Control Firewall Management support.. |
