IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Issue with inspection engine

  • 1.  Issue with inspection engine

    Posted Sun February 23, 2020 02:26 PM
    Hi,

    I have an issue verifying certain inspection engine running on MySql database servers (virtual machines), with pre-configuered database settings etc. 
    The error I get is:  I get the 7 succes but with the error Coulndt connect to the inspection engine on S-TAP host etc... So the S-TAP is reachable be not logging properly. 

    What I have tried so far:
    • Advanced verification with correct DB credentials - the Test conenction works and successfully connects to the DB but still cannot verify.
    • Tried different policies to catch the Login failed and/or the SQL error (also check the inspection engine config where the box to log login failed is ticked. Also tried different criterias to catch from that certain server with both host name and host ip.
    • The firewall accepts the connection 
    • Upgrading the S-TAP
    • Different ports 
    • Check the reports if there is any session for the server
    Anyone have any suggestion what could be wrong?

    I have been follwing this link = https://www.ibm.com/support/pages/what-do-if-guardium-inspection-engine-status-fail to troubleshoot. 

    Current environment is runing:
    Guardium 11.1
    S-TAP/A-TAP/K-TAP 11
    GIM 11

    Thanks in advanced. 


  • 2.  RE: Issue with inspection engine

    Posted Mon February 24, 2020 02:55 AM

    Described behavior can be tied with timeout or policy issue

    STAP verification bases on correlation generated traffic and audit events gathered by agent.

    Please check few things:

    - does your policy gathers events generated by verification? If you see them in report probably you have problem with timeout. If the events are not visible you must change policy to audit them

    - does standard verification works?

    - do you see login error generated by standard verification?

    Verification process waits a while for audited events and if they are not visible the error is generated in the last stage.

    To solve problem the best solution would be expansion of this timeout - unfortunatelly not available in Guardium settings.

    If my suggestion is correct - you should receive successful verification from time to time.



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 3.  RE: Issue with inspection engine

    Posted Mon February 24, 2020 11:56 AM
    I look through my configuration and noticed that my Ktap and Atap was not enabled - I have now enabled both of them (think that resolved part of my issue). Now i recieve logs from the dbserver according to my policy. However, I am not able to verify my inspection engine even though i recieve logs including when Failed logins are performed by me and other events. 

    When I perform a standard verification I the following message: S-TAP verification completed. The S-TAP is not monitoring network database traffic - but it does?

    I have increased the store stap network_latency 99 but it didnt solve my issue. 

    I have tried different policies which all are able to catch if I create a Failed login but the one created by the verfication of the inspection engine. 

    I think my issue is that the policy is not catching the failed login performed by the inspection engine but I have tried different policies to try and catch it but with no luck . Any ideas what could be wrong?






  • 4.  RE: Issue with inspection engine

    Posted Mon February 24, 2020 12:27 PM
    For a while - create simple policy to audit everything and check results.

    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 5.  RE: Issue with inspection engine

    Posted Tue February 25, 2020 09:14 AM
    Created a simple policy which cataches my manual failed logins and sql errors but not the inspection engine.

    Created the following policy:
    *Selective audit trail
    *Rule type - exception
    *Critieria - Exception type = LOGIN_FAILED, severeity = info 
    *Critieria - Exception type = SQL_ERROR, severeity = info


  • 6.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 02:33 AM
    Add one more rule Access one to log everything.

    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 7.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 03:11 AM
    Created the following Access policy
    Rule type: Access
    Rule criteria: none
    Rule action: Log

    I can see a lot of logs coming in from different sources including the db server that I am troubleshooting but the inspection engine still does not verify.

    Any idea to uninstall the Stap,ktap and atap and install them again?


  • 8.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 03:21 AM
    STAP reinstallation probably is not a solution.
    Still consider that problem can be related to timeout.


    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 9.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 08:23 AM
    Are there any logs on the fileserver that I can read to give me a hint what the problem could be? I still have the maxium stap network_latency and tried with lower value. Since I do recieve logs it is not critical to solve the issue but it is annoying have a failed inspection engine.


  • 10.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 08:42 AM
    STAP network latency is not relevant to this issue.
    I am talking about timeout related to visibility a parsed data on collector.
    If your collector is very busy the Inspection Engine Verify will not get results before built-in timeout for this operation is raised.


    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 11.  RE: Issue with inspection engine

    Posted Wed February 26, 2020 09:10 AM
    I see, well the collector is not very busy since I only have a few sources connected with limited activity.
    Thanks for the feedback, I will continue with my troubleshooting and let my know if you have any ideas.