- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Authentication log request
One of our AM Primary consoles is posting continuous error messages in the Authentication Monitor 1-2x per minute.
Activity Key: Authentication Log Request
Description: Log request received from agent “Primary Console Address” with IP address “x.x.x.x” in security domain “SystemDomain”
Reason: Syntax Error
User ID: SYSTEM
I searched and found this page, and it shows the same error, but I don't think it helps us: https://community.rsa.com/docs/DOC-46250
- Tags:
- 000028896
- Agent
- Agents
- Auth Agent
- Authentication Agent
- Authentication Manager
- Community Thread
- Discussion
- Forum Thread
- log request received from agent
- RSA SecurID
- RSA SecurID Access
- SecurID
- syntax error
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What do you know about the agent from which these events are being received? If this agent is not a legitimate agent, I would recommend you remove it from your Authentication Manager configuration. AM will simply discard the "log request" protocol from an unknown agent.
If the agent is a well-known agent, I would check if some automated process is attempting to send data to the login interface at the agent. The "syntax error" log is generated by agents after experiencing some number of authentication attempts with passcode data that the agent identifies as not possibly being a passcode. For example, a passcode longer than 16 character or containing unsupported characters.
I would login to the agent generating the log event, enable verbose agent logging (or network-level data capture with something like "Wireshark"), and examine those logs for additional clues as to the source of the problem. Even if you do simply remove the agent, I would probably investigate the IP address, what is running it,and the system from which the network traffic is being sent.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The agent is itself - the Primary RSA AM Console. It's saying the log request is from itself.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version and patch level ? Could be a minor bug that was remedied.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AM 8.2 SP 1 P 06
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I checked the daily log under /opt/rsa/am/radius, and was able to see that the error was related to another host than the one the error was reporting in the Auth Monitor.
