IBM Security QRadar

 View Only
  • 1.  Error Code: 10057 on Wincollect Agent

    Posted Thu March 25, 2021 04:40 AM
    Hello,

     I have installed Wincollect Agent countless times, but it is not connected to the IBM-Qradar SIEM server. I did netstat on the IBM-Qradar Server on port "8413" with no output on this port number. 

    Kindly see the error message below.
    image.png

    Thank you.

    Best regards,
    Oyindamola


  • 2.  RE: Error Code: 10057 on Wincollect Agent

    Posted Thu March 25, 2021 07:03 AM
    1.) Verify that the wincollect rpm is installed on the IBM QRadar

    yum list all | grep -i AGENT-WINCOLLECT

    2.) Restart the wincollect service, verify the logs again
    3.) Verify the version of wincollect on IBM QRadar SIEM and the version installed on the managed host, it should be compatible

    ------------------------------
    Namit Maurya
    ------------------------------



  • 3.  RE: Error Code: 10057 on Wincollect Agent

    Posted Fri March 26, 2021 10:05 AM
    Hello, Maurya,

    I have tried step 1. Here is the output of the command below.
    image.png
    I restarted the wincollect service  and the Windows client, kindly see the log file below.
    image.png
    Here is the version of wincollect installed on IBM QRadar SIEM and the managed host.
    image.png

    Kindly help with resolvable options.

    Thank you.

    Best regards,
    Oyindamola





  • 4.  RE: Error Code: 10057 on Wincollect Agent

    Posted Fri March 26, 2021 12:14 PM
    1.)Try to telnet QRadar On port 8413 from windows host. It should be able to reach QRadar on port 8413


    2.) Deploy full configuration and choose to restart event collection services
     Most probably the issue is with the 8413 connectivity from host to QRadar

    Try and see if you are able to find the root cause.


    ------------------------------
    Namit Maurya
    ------------------------------



  • 5.  RE: Error Code: 10057 on Wincollect Agent

    Posted Tue March 30, 2021 04:55 AM
    Hi Maurya,

    Thanks for your response.

    I did telnet QRadar on port "8413" from windows host. It is a connection failure.
    image.png
    I have performed Deploy full configuration alongside restart event collection services, but nothing is reflected on the QRadar server.

    I did netstat on the QRadar server, the wasn't any response from the command.
    image.png

    Are there any other necessary configurations I need to do?

    Thank you.

    Regards,
    Oyindamola