IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  event collectors dont send logs

    Posted Fri February 26, 2021 01:34 PM

    Hi.

    We have serious issues. Event collectors/processors stop sending logs to Console, port 514 on all servers is not in LISTEN mode. We checked almost everything : Network congfigurations, firewalls, Full configuration deployment, Restarting Web Servers, reconfiguring network configurations but it didn't help. Event collectors/processors, hostcontext, syslog-ng services are also started. Please, assist.



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: event collectors dont send logs

    Posted Fri February 26, 2021 05:13 PM

    Support Member

    Do you have your QRadar version? There is a known issue where the logs write a "Waiting for license..." issue in the collection service (ecs-ec-ingress). I would verify that you've run the command in this Flash Notice that went out to all users.

    What to do:

    1. Read this technical note: https://www.ibm.com/support/pages/node/6395080
    2. Run the command with all_servers.sh in Step 2, command #1 on your Console appliance. This all_servers command will update all appliances in the deployment.
    3. Wait a few minutes for the updates to take place.
    4. Verify in the Log Activity tab that you see events.

    I would start by running the command listed. If you continue to have issues, open a case and set it to Severity 1 / System down. If you need to escalate your case, request a Duty Manager here using this procedure: https://www.ibm.com/support/pages/node/571863



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: event collectors dont send logs

    Posted Fri February 26, 2021 05:35 PM

    We use 7.2.8 version which is not supported anymore. Can we apply it in this version?



    #QRadar
    #Support
    #SupportMigration


  • 4.  RE: event collectors dont send logs

    Posted Tue March 02, 2021 03:23 PM