|Applies To||RSA Product Set:- Security Analytics |
RSA Product/Service Type:- Remote log collector,Log Decoder, Local Collector
|Issue||The error message below occurs when going to the Config tab of a Remote Collector.|
One or more custom log decoder event processors exist. You may delete them by going to the explore view menu.Note that any of the event data stored in a queue will be lost as the result of a delete operation.
[LogdecoderProcessor] [failure] [queue.checkpoint] [processing] [Receiver WorkUnit] [processing] LogDecoder processor error from queue LogDecoder.SG_HK.checkpoint at location 127.0.0.1:5671. Reason: Consumer was cancelled: amq.ctag-dTKvrwnUsqdo0ipZS2imCw Jun 3 05:49:25 srahkgsav99 NwLogCollector: [LogdecoderProcessor] [failure] [queue.checkpoint] [processing] [Receiver WorkUnit] [processing failure] srxhkrsalh01-LogDecoder:WrkUnit Processing failed
In addition, you can see two queues for each collection with active consumers, which can be verified by issuing the command below on the VLC.
rabbitmqctl list_queues -p logcollection consumers name messages
The error can also occur when switching a VLC type from "LC" to "RC", and there is some remaining Local Collector configuration.
For more information refer to the following knowledge article: RSA Security Analytics syslog option is missing on a virtual log collector (VLC) in version 10.6
|Cause||A possible cause is due to a manual adding of a secondary event processor to forward logs out to a non-SA system.|
This can be confirmed in the RSA Security Analytics UI by navigating to Services > VLC > Explore view > Event Processor.
How to delete the customized event-processor from explore view of remote collector
This will automatically delete the unwanted queues and will start processing the messages to the local collector.