000032950 - RSA Security Analytics Decoders initialization error due to incorrect packet.dir values

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000032950
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: SA Core Appliance, SA Packet Decoder, SA Log Decoder
RSA Version/Condition: 10.X
 
IssueDecoder capture is not starting. By navigating to Decoder->System page, can see "initialization error".
CauseIncorrect packet.dir value is one of the causes of initialization error which can be tracked as below.
/var/log/messages:
Apr 14 12:56:50 FDALADCNWSAD-IINET NwDecoder[31562]: [Engine] [failure] Module decoder failed to load: The directory '/var/netwitness/decoder/packetdb0/packetdb' does not exist 
Apr 14 12:56:50 FDALADCNWSAD-IINET NwDecoder[31562]: [Engine] [failure] Module decoder failed to load: Diagnostic information: Throw in function void nw::ObjectStoreDatabase<ObjectStoreT>::initDbStorageNl(const DbStorageLocations&) [with ObjectStoreT = nw::ObjectStoreIndex<nw::PacketData, nw::PacketManifest>; nw::DbStorageLoc 
ResolutionPlease follow below steps to resolve the issue.
 
A. If GUI Explore view accessible:
 

1. Login to GUI as administrator.
2. Navigate to Administration->Services->Decoder->View->Explore.
3. In the Explore view, Left hand side expand database->Config. Right hand side, packet.dir value can be adjusted according to customer set up.

- In this particular issue, There will not be packetdb under /var/netwitness/decoder/packetdb0.

4. Restart the service using restart nwdecoder to take the new values.

B. If GUI Explore view is not accessible:
 
1. Login to Putty session of decoder.
2. Stop Decoder service using stop nwdecoder command.
3. Run cd /etc/netwitness/ng command to access decoder configuration file.
4. Modify NwDecoder.cfg file using vi editor to adjust packet.dir value.
5. Start decoder service using start nwdecoder command.

Attachments

    Outcomes