curtisi wrote:
There's also a big drop in your "Events per Minute" chart. Have you run a Database Maintenance in the Reports console to see if events are still getting into the database? If you run a DISKUSAGE under the APPLIANCE menu, are there events being queued? Do you have a partition close to or at 100% full?
The events per minute are still active, its just i caught it at the start of the counter (set at a constant/live update) so every minute it moves over. As for disk space its running on a a separate array from the OS drive and has about 400GB space where the image and database is all stored.
curtisi wrote:
The sample data usually shows up when there's no real data for the time period. The first thing I'd check in this scenario, though, is the date config on the LEM. Under the APPLIANCE menu, enter DATECONFIG and then hit enter four (4) times. The LEM will return the current date, time and timezone. Are these correct? Are they drifting over the course of 24 hours to 15 days? By default the LEM syncs with the virtual machine host for the time. Is your host set to sync with a good NTP source? Your system info says GMT and your profile says the UK, but I would start there.
I've taken a look at this now as its actually happened again probably around an hour since I posted this thread but the time is being shown correctly although I'll have to check when it next fails. The problem is that it basically fails at any point so its hard to diagnose. Typically the error says something along the lines of failed to retrieve something (i'll find out exactly next time it goes on the blink as i know that's a bit unhelpful) when I hover over the red attention icon. Once the appliance is restarted all data in-between it working and giving the "sample data" notice is displayed which makes it a tad confusing.