cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
egas84
Level 7
Report Inappropriate Content
Message 1 of 8

Questions about data source monitoring in case of log shipping failure.

Hi all, 

Is it possible to monitor a data source so that when events stop we can get an alert?

 

Regards, 

Edgar

7 Replies
Bluefish
Level 9
Report Inappropriate Content
Message 2 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Hi Edgar,

Any inactive datasource will show in the device tree on Flash with a Yellow flag. You can also setup an alarm for datasource inactivity.

Add a new Alarm, the condition will be "device status change", Health monitor Status : Idle Time

The actual idle time the alarm will take is the inactivity threshold set for each receiver. this can be found under Properties, Events, Flows & Logs, Inactivity settings. The default is 30 minutes.

You can change this setting for each Datasource.

HTH

Dorothée

 

gbarbosa
Level 8
Report Inappropriate Content
Message 3 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Hello,

Thank you very much for your answer.
We've followed the procedure you mentioned but we are having some trouble.
We are receiving alarms of data sources that are not failing, let me give you an examples:

Correlation Data Source:

Note: We configured threshold of 15 minutes for Correlation Data Source.

1. As you can see from the screenshot (Alarm_Trigger_Data_Source_Correlation.PNG) we had an alarm trigger for the "Correlation" Data Source at 19 Oct 2022 12:06:50pm.
2. If we check the event graphics (Events_Data_Source_Correlation_1.PNG,Events_Data_Source_Correlation_2.PNG) we can see that there is not a time in which this log source fails for 15 minutes.
3. This situation keeps repeating. We keep receiving alarms and not seeing data source failure for 15minutes.

What do you think that is causing this issue?
Is 15 minutes a threshold too short for the SIEM to handle? Do you know if there are any other causes for this?
I've attached the alarm configuration and Inactivity Settings for this example I gave you.
Could you help us with this situation?

Thank you very much.
Best regards,
Goncalo

 

gbarbosa
Level 8
Report Inappropriate Content
Message 4 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Here is the rest of the attachments

gbarbosa
Level 8
Report Inappropriate Content
Message 5 of 8

Re: Questions about data source monitoring in case of log shipping failure.

More attachments

gbarbosa
Level 8
Report Inappropriate Content
Message 6 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Last attachments

Bluefish
Level 9
Report Inappropriate Content
Message 7 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Hi Edgar,

I did not ask your version but will assume you are on v11.x

I believe the inactivity alarms are firing on the ESM. So if the events are coming in on a receiver or correlation engine but the ESM does not have them, the Idle alarm will fire.

So if you have an alarm set for 15 minutes inactivity and the auto-publish time for the device is 15 minutes or more , then you are likely to have false positive.

Thanks

Dorothée

gbarbosa
Level 8
Report Inappropriate Content
Message 8 of 8

Re: Questions about data source monitoring in case of log shipping failure.

Hello,

 

I verified what you said and you are right.

 

Thank you so much for your help.

Best regards,

Goncalo

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community