I look through my configuration and noticed that my Ktap and Atap was not enabled - I have now enabled both of them (think that resolved part of my issue). Now i recieve logs from the dbserver according to my policy. However, I am not able to verify my inspection engine even though i recieve logs including when Failed logins are performed by me and other events.
When I perform a standard verification I the following message: S-TAP verification completed.
The S-TAP is not monitoring network database traffic - but it does?
I have increased the
store stap network_latency 99 but it didnt solve my issue.
I have tried different policies which all are able to catch if I create a Failed login but the one created by the verfication of the inspection engine.
I think my issue is that the policy is not catching the failed login performed by the inspection engine but I have tried different policies to try and catch it but with no luck . Any ideas what could be wrong?
Original Message:
Sent: Mon February 24, 2020 02:55 AM
From: Zbigniew (Zibi) Szmigiero
Subject: Issue with inspection engine
Described behavior can be tied with timeout or policy issue
STAP verification bases on correlation generated traffic and audit events gathered by agent.
Please check few things:
- does your policy gathers events generated by verification? If you see them in report probably you have problem with timeout. If the events are not visible you must change policy to audit them
- does standard verification works?
- do you see login error generated by standard verification?
Verification process waits a while for audited events and if they are not visible the error is generated in the last stage.
To solve problem the best solution would be expansion of this timeout - unfortunatelly not available in Guardium settings.
If my suggestion is correct - you should receive successful verification from time to time.
------------------------------
Zbigniew (Zibi) Szmigiero
IBM
Warsaw
Original Message:
Sent: Sun February 23, 2020 02:26 PM
From: Herman
Subject: Issue with inspection engine
Hi,
I have an issue verifying certain inspection engine running on MySql database servers (virtual machines), with pre-configuered database settings etc.
The error I get is: I get the 7 succes but with the error Coulndt connect to the inspection engine on S-TAP host etc... So the S-TAP is reachable be not logging properly.
What I have tried so far:
- Advanced verification with correct DB credentials - the Test conenction works and successfully connects to the DB but still cannot verify.
- Tried different policies to catch the Login failed and/or the SQL error (also check the inspection engine config where the box to log login failed is ticked. Also tried different criterias to catch from that certain server with both host name and host ip.
- The firewall accepts the connection
- Upgrading the S-TAP
- Different ports
- Check the reports if there is any session for the server
Anyone have any suggestion what could be wrong?
I have been follwing this link = https://www.ibm.com/support/pages/what-do-if-guardium-inspection-engine-status-fail to troubleshoot.
Current environment is runing:
Guardium 11.1
S-TAP/A-TAP/K-TAP 11
GIM 11
Thanks in advanced.