|Applies To||SA Product Set: Security Analytics|
RSA Product/Service Type: Virtual Log Collector, Windows Legacy Collector
RSA Version/Condition: 10.x
O/S Version: CentOS 6
|Issue||The Security Analytics Virtual Log Collector is failing to send events to the Local Log Collector.|
/var/log/messages in the Virtual Log Collector shows an error similar to the following:
Feb 26 17:48:38 vlc nw: [BufferedChannel] [failure] An error occurred publishing to an AMQP channel: NO_ROUTE, exchange: sdee, routing key: sdee
The error above means that the Virtual Log Collector is receiving sdee events but is unable to send these events to the Local Log Collector.
|Cause||This issue is caused if:|
In fact only File and Windows collections are configured in this case.
The same issue may occur if the Local Log Collector is configured to pull logs from the Virtual Log collector as shown below:
|Resolution||If the Virtual Log Collector is pushing logs to the Local Log Collector:|
If the Local Log Collector is pulling logs from the Virtual Log Collector:
|Notes||The same error may be caused by another issue described in the following KB article:|
Security Analytics Log collection fails with the error message "An error occurred publishing to an AMQP channel: NO_ROUTE" in RSA Security Analytics 10.4