000017622 - Error message 'Index org.src has exceeded value threshold' on an RSA NetWitness concentrator

Document created by RSA Customer Support Employee on Jan 10, 2017Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000017622
Applies ToRSA NetWitness NextGen
RSA NetWitness NextGen 8.6
RSA NetWitness Concentrator
RSA NetWitness Administrator
IssueError message "Index org.src has exceeded value threshold" on RSA NetWitness appliances.

While utilizing the system you may find the performance is degrading and checking the concentrator.log file you find multiple entries per day similar to the examples below.

  • (W) 2009-Sep-18 02:12:36 [Index]  Index org.src has exceeded value threshold of 20000, dropping 2000 of the oldest values
  • (W) 2009-Sep-18 02:12:36 [Index]  Index org.dst has exceeded value threshold of 20000, dropping 2000 of the oldest values
  • (W) 2009-Sep-18 02:12:36 [Index]  Index domain.src has exceeded value threshold of 20000, dropping 2000 of the oldest values
  • (W) 2009-Sep-18 02:12:36 [Index]  Index domain.dst has exceeded value threshold of 20000, dropping 2000 of the oldest values
CauseThis issue occurs because the default values for the domain and organization index keys need to be adjusted.
Resolution

Utilize NetWitness Administrator to connect to the concentrators and edit the file index-concentrator.xml via the "File Configuration Editor". Locate the key descriptions"Source Domain", "Destination Domain", "Source Organization", and "Destination Organization". Modify these entries to the following:

<key description="Source Organization" level="IndexValues" format="Text" name="org.src" valuePages="1451520" totalPages="3841200" valueMax="100000" />
<key description="Destination Organization" level="IndexValues" format="Text" name="org.dst" valuePages="1451520" totalPages="3841200" valueMax="100000" />
<key description="Source Domain" level="IndexValues" format="Text" name="domain.src" valuePages="1451520" totalPages="3841200" valueMax="80000" />
<key description="Destination Domain" level="IndexValues" format="Text" name="domain.dst" valuePages="1451520" totalPages="3841200" valueMax="80000" />

Once the edits have been saved the concentrator will need to be restarted. Do the following to restart the concentrator. Stop all aggregation via the NetWitness Administrator. Ensure all aggregation is stopped by checking the log file for "Aggregation threads have completed".

Then perform a "Restart Server" from the "System Settings" screen for the concentrator. Check whether or not aggregation starts after the service comes back up and start it manually if it doesn't.

Legacy Article IDa58578

Attachments

    Outcomes