000029577 - Duplicate queue called "Logdecoder" appears on event processors after an upgrade for RSA NetWitness Platform

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Oct 1, 2019
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000029577
Applies ToRSA Product Set: RSA NetWitness Platform
RSA Product/Service Type: Log Collector, Log Decoder
RSA Version/Condition: 10.6.x, 11.x
IssueLog Decoder / Log Collector appliances which are upgraded from older versions of Netwitness may contain a script that causes the incorrect creation of 2 queues of similar names: "Logdecoder" (with a capital  "L") and "logdecoder" (with a lower case "l").  Should this occur, the named queue with the upper case "L" should be removed.

ResolutionTo remove the duplicate Log Decoder queue on event processors do the following from the SA UI as an administrative account:
  1. Go to Explore view of the Log Collector or Log Decoder device, then expand the event processors -> right click on the Logdecoder select properties -> on the properties section, then on the drop down menu select stop 
  2. Go to event processors -> right click properties -> on the properties section on the drop down menu, select remove from the parameters box, then type name=Logdecoder and then click Send
  3. This can take a few minutes to complete. After completion, refresh the web page, then check the Explorer -> expand the event processors.  Only the logdecoder with small "l" should be present.