A few days ago, our ESA service went down. While I was able to restart the process, I'm attempting to determine what happened to it. I've gone through the log files in the following locations and did not find any OOM or other errors that would indicate the root cause. Are there any other logs or locations on the ESA server I could search?
/var/log/messages
/opt/rsa/esa/logs/esa.log.*
Hi you could also have a look in:
/opt/rsa/esa/wrapper.log
Common reasons for the ESA going down are rogue ESA Rules exhausting all available memory.