Log Collection: Troubleshoot

Document created by RSA Information Design and Development on Sep 11, 2017Last modified by RSA Information Design and Development on Oct 12, 2017
Version 7Show Document
  • View in full screen mode

This topic describes the format and content of Log Collection Troubleshooting. NetWitness Suite informs you of Log Collector problems or potential problems in the following two ways.

  • Log files.
  • Health and Wellness Monitoring views.

Log Files

If you have an issue with a particular event source collection protocol, you can review debug logs to investigate this issue. Each event source has a Debug parameter that you can enable (set parameter to On or Verbose) to capture these logs.

Caution:  Only enable debugging if you have a problem with this event source and you need to investigate this problem. If you have Debug enabled all the time it will adversely affect the performance of the Log Collector.

Health and Wellness Monitoring

Health and Wellness monitoring makes you aware of potential hardware and software problems in a timely manner so that you can avoid to outages. RSA recommends that you monitor the Log Collector statistical fields to make sure that the service is operating efficiently and is not at or near the maximum values you have configured. You can monitor the following statistics (Stats) described in the Admin > Health & Wellness view.

Sample Troubleshooting Format

RSA NetWitness Suite returns the following types of error messages in the log files for.

Log Messages

timestamp failure (LogCollection) Message-Broker Statistics: ...

timestamp failure (AMQPClientBaseLogCollection): ...
timestamp failure (MessageBrokerLogReceiver): ...

Possible Cause

The Log Collector cannot reach the Message Broker because the Message Broker:

  • stopped running.
  • has erroneous connection settings.
  1. <use the="the" systemctl="systemctl" command="command" on="on" console="console" to="to" check="check" status="status" of="of" message="message" broker="broker" shell="shell" console.="console.">returns the following if the message broker is not running:</use>

            prompt$ systemctl status rabbitmq-server

            rabbitmq start/running, process 10916

  1. Start the RabbitMQ Message Broker on event-broker node in the Explore view:

    Example shows starting the RabbitMQ Message Broker on the event broker node in the Explore view.

You are here
Table of Contents > Log Collection: Troubleshoot