000031933 - Cannot see the Archiver in Data Sources when testing a rule in RSA Security Analytics

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000031933
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Archiver, Security Analytics UI, Reporting Engine
RSA Version/Condition: 10.5.x
Platform: CentOS
O/S Version: EL6
IssueWhen configuring a Reporting Engine rule, the user cannot see the Archiver in the available data sources.
CauseThis issue occurs when the Archiver data source is not properly added in the Security Analytics UI.  The information stored in Security Analytics for the service and the information stored in reporting engine for the same service do not match.
Therefore, when a user creates a Reporting Engine rule in the Security Analytics UI, the SA Server skips the Archiver because it cannot identify the correct data source based on the information provided by the Reporting Engine.
ResolutionThis issue has been addressed in Security Analytics 10.5.1.2.
WorkaroundTo resolve the occurrence, perform the steps below.
  1. Log in to the Security Analytics UI as an administrative user.
  2. Go to Administration > Services > Reporting Engine > View > Config > Sources.
  3. Remove the Archiver data source and re-add it.

Attachments

    Outcomes