I've recently configured the Kaspersky Security Center using the guide available at https://community.rsa.com/docs/DOC-40208.
We're using the ODBC connection to the database, but I'm not sure if any data is being collected.
Can anyone help me figure out how to check this?
Thank you for your help.
Assuming that the test connect worked, and there is data to be collected....
First. Does the IP or hostname show up under either device.ip or device.host?
Second. On the Log Collector check under /var/netwitness/logcollector/runtime/odbc/eventsources/ You should see a file that references your device. Open the file and see if the event traking id section is filled out.
If the file has the proper date or tracking ID, I would open SQL manager and maker sure there is new data in there post collection setup time.
Can you check those and report back?
Thank you for your quick reply.
Yes, I got a "Test connection successful" message when setting up the source. Going through your suggestions:
1) I couldn't find the device IP or hostname in the mentioned meta keys.
2) The folder "odbc" doesn't exist under "/var/netwitness/logcollector/runtime/".
What am I doing wrong? Do I need to restart the log collector?