Hello,
There are multiple reasons why you may not see the new logs after reboot.
1> Checking services on the EP
a. ssh to the console and then to EP from which you do not see events.
b. Check the status of hostcontext and ecs-ec-ingress service :
systemctl status hostcontext
systemctl status ecs-ec-ingress
c. If they are inactive restart them.
systemctl restart hostcontext
systemctl restart ecs-ec-ingress
2 > You should check if there are any System Notifications related to EP on the QRadar Console GUI.
3> You should check the disk space on the EP and see if there are any errors reported for ecs-ec or ecs-ec-ingress in the /var/log/qradar.log file.
If you find any details let us know.
The best way would be to open a Support Case with QRadar Team so that they can analyze the EP logs and help you with this issue, as the solution depends on what error you are hitting.
Thanks,
Ashish
#QRadar#Support#SupportMigration