|Applies To||RSA Product Set: NetWitness Logs & Network|
RSA Product/Service Type: Virtual Log Collector (VLC), Windows Legacy Collector (WLC)
RSA Version/Condition: 10.6.x, 11.x
O/S Version: CentOS
|Issue||The Virtual Log Collector or Window Legacy Collector is failing to send events to the Local Log Collector.|
The /var/log/messages file in the Virtual Log Collector shows an error similar to the following:
The error above indicates that the Virtual Log Collector is receiving SDEE events but is unable to send these events to the Local Log Collector.
|Cause||This issue is caused if:|
In this example only File and Windows collections are configured.
The same issue may occur if the Local Log Collector is configured to pull logs from the Virtual Log collector as shown below:
|Resolution||If the Virtual Log Collector is pushing logs to the Local Log Collector:|
If the Local Log Collector is pulling logs from the Virtual Log Collector:
|Notes||The same error may be caused by another issue described in the following article:|
Security Analytics Log collection fails with the error message "An error occurred publishing to an AMQP channel: NO_ROUTE" in RSA Security Analytics