Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM agent question

$
0
0

Well I figured I would try one more time before I open a support ticket.  We still have 3 or 4 agent machines that were connected to LEM at one time but for whatever reason refuse to re-establish the connection again.  I have tried the usual stopping the service, deleting the spop folder, and starting the service.  I tried uninstalling and re-installing the agent via the local tool.  Tried removing the agent then deploying via the remote agent.  So far nothing.  Still the same errors.  I'm able to telnet to the LEM box on the necessary ports in the .conf file, using the IP and DNS name.  Any ideas? Here is the log output. 

 

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {SPOP:8} Starting TriGeo Agent (Release 5.3.1) build [1];

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [SpopModule v24798] {SPOP:8} build server version string: 5.3.1-CORE_132.25174.51;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [InDepthConfigProps v24744] {SPOP:8} nDepth enabled via default because InDepthEnable not present;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [InDepthConfigProps v24744] {SPOP:8} indepth.conf not found at C:\WINDOWS\SysWOW64\ContegoSPOP\indepth.conf;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [RawDataClient v24744] {SPOP:8} Status Inactive;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {SPOP:8} Initializing database;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {SPOP:8} Database Initialized;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {Initialize Communications:10} Initializing Agent communications;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {Initialize Tools:13} Initializing ToolAPI;

(Fri Jul 26 08:56:36 CDT 2013) II:NOTICE [Contego] {Initialize Tools:13} Initializing FAST;

(Fri Jul 26 08:56:36 CDT 2013) WW:STATUS [Communications] Operating System == Windows Server 2008;6.0;x86

(Fri Jul 26 08:56:40 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {Initialize Communications:10} CheckUSBDefender returned installed and running;

(Fri Jul 26 08:56:40 CDT 2013) DD:DEBUG 1 [Communications] Max number of agent install attempt property is not a numerical value, default to 10

(Fri Jul 26 08:56:40 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Making install request to: 172.20.0.167;

(Fri Jul 26 08:56:41 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Install request completed (favorably);

(Fri Jul 26 08:56:41 CDT 2013) WW:STATUS [Communications] This entity has got its certificate signed by the parent.

(Fri Jul 26 08:56:41 CDT 2013) WW:STATUS [ComModule] Opening installed connection to parent.

(Fri Jul 26 08:56:41 CDT 2013) II:NOTICE [NioCenter v23873] {ComModuleSpop:20} Initializing Nio Center.;

(Fri Jul 26 08:56:41 CDT 2013) II:NOTICE [NioCenter v23873] {NioComNetworkParent:21} Nio Center successfully initialized.;

(Fri Jul 26 08:56:41 CDT 2013) II:NOTICE [NioCenter v23873] {NioComNetworkParent:21} Nio Center Connecting.;

(Fri Jul 26 08:57:02 CDT 2013) EE:ERR [NioSelector v23873] {NioComNetworkParent:21} Connection status: Unable to complete nio  connection to address 172.20.0.167/37892  Connection timed out: no further information;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [NioCenter v23873] {NioComNetworkParent:21} Closing Nio Center: Nio Thread has stopped;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [DecryptRouter v23873] {NioDecryptRouter:23} DecryptRouter exiting;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [EncryptRouter v23873] {NioEncryptRouter:24} EncryptRouter exiting;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [Communications] {ComModuleSpop:20} Parent disconnection signaled: ( id:0 ):  Disconnect reason: Unable to initialize;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} niocenter is null;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Closed connection to manager: Unable to initialize;

(Fri Jul 26 08:57:02 CDT 2013) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Failed opening nio connection to manager '172.20.0.167';

(Fri Jul 26 08:57:03 CDT 2013) II:NOTICE [Contego] {Initialize RCC Server:12} Initializing the Tool Message Center;

(Fri Jul 26 08:57:03 CDT 2013) II:NOTICE [Contego] {Initialize Secret Center:11} Initializing the secret center;

(Fri Jul 26 08:57:03 CDT 2013) II:NOTICE [Contego] {Initialize RCC Server:12} Initializing the Tool API Command Center;

(Fri Jul 26 08:57:03 CDT 2013) WW:STATUS [FastEvaluator] Added ToolId:NtSystem

(Fri Jul 26 08:57:03 CDT 2013) WW:STATUS [FastEvaluator] Added ToolId:NT Application

(Fri Jul 26 08:57:03 CDT 2013) WW:STATUS [FastEvaluator] Added ToolId:VistaSecurity

(Fri Jul 26 08:57:03 CDT 2013) DD:DEBUG 2 [ComModuleSpop] Entering new stuck message into hash: 800

(Fri Jul 26 08:57:03 CDT 2013) II:NOTICE [LogManagementRegistryClient v23873] {ComModuleSpop:20} parentDisconnected;


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>