- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Not receiving logs from McAfee ePO 5.x
I'm trying to integrate McAfee ePO with RSA SA 10.6.4.1.
I've created the DSN with the DB and server name, and port number. Left the driver value as default.
I've also entered the ODBC username and password configuration parameters, and tested connection - successful.
However, I receive no logs from McAfee ePO. I looked up the /var/log/messages file, and I find the following warning -
NwLogCollector[24339]: [OdbcCollection] [warning] Invalid audit log format for:Test Connection Success!
I'm not sure what this means.
Need assistance.
- Tags:
- Community Thread
- Discussion
- Forum Thread
- mcafee_epolicy_orchestrator®_(epo™)
- NetWitness
- NetWitness Orchestrator
- netwitness-logs
- NW
- NWO
- NWP
- odbc
- Orchestration
- Orchestrator
- RSA NetWitness
- RSA NetWitness Orchestrator
- RSA NetWitness Platform
- rsa sa
- SOAR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
McAfee EPO has many different modules in it.
Which module are you trying to collect from? AV? HIDS?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Dave,
The AV module. We're going for the system and virus logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Visham,
Please consider upgrading from 10.6.4.1 to a version of NetWitness 11.x the 10.6.x.x versions will be End of Life in October 2019. You must upgrade to a version of 10.6.6.x prior to upgrading to 11.3.
Here is some documentation pertaining to NetWitness 11.3 features and functionality:
v11.3 Release Notes
https://community.rsa.com/docs/DOC-100363
NetWitness Known Issues (11.x)
https://community.rsa.com/community/products/netwitness/documentation/known-issues
Introduction Blog Post (Marketing)
Physical Host Upgrade Checklist 10.6.6.x to 11.3
https://community.rsa.com/docs/DOC-101413
Physical Host Upgrade Guide 10.6.6.x to 11.3
https://community.rsa.com/docs/DOC-100385
Update Guide 11.x.x.x to 11.3
https://community.rsa.com/docs/DOC-100381
Getting Started Guide
https://community.rsa.com/docs/DOC-100377
NetWitness Respond User Guide
https://community.rsa.com/docs/DOC-99944
NetWitness Investigate Quick Start Guide
https://community.rsa.com/docs/DOC-101213
NetWitness UEBA Quick Start Guide
https://community.rsa.com/docs/DOC-100550
NetWitness Endpoint Quick Start Guide
https://community.rsa.com/docs/DOC-100167
Changes to ESA script outputs
Threat-Aware Authentication:
Recovery Tool User Guide
https://community.rsa.com/docs/DOC-101457
Kind regards,
Steve
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Have you followed the guide here? https://community.rsa.com/docs/DOC-40219
There are a couple of different options to pick depending on AV version
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Dave, it's working now! just took a while to manifest.
