The Crash Reporter is an optional service for Security Analytics services. When activated for any of the core services, the Crash Reporter automatically generates a package of information to be used for diagnosing and solving the problem that resulted in the service failure. The package is automatically sent to RSA for analysis. The results are forwarded to RSA support for any further action.
The information package sent to RSA does not contain captured data. This information package consists of the following information:
The Crash Reporter crash analysis can be activated for any Core product.
The crashreporter.cfg File
One of the files available for editing in the Service Config view > Files tab is crashreporter.cfg, the Crash Reporter Client Server configuration file.
This file is used by the script that checks, updates, and builds crash reports on the host. The list of products to monitor can include Decoders, Concentrators, hosts, and Brokers.
This table lists the settings for the crashreporter.cfg file.
applicationlist=decoder, concentrator, host
Define the list of products to monitor.
Location of the site directory for the report.
Location of the web directory.
Location of the development directory.
Location of the directory storing data files.
Location of the perl files.
Location of the binary executables.
Location of the binary libraries.
Location of the configuration files.
Location of the log files.
Location of the directory containing scripts.
Location of the process work directory.
Location where created sql files are placed.
Location where temporary reports are created.
Location of the created package files.
Location of the gdb configuration file.
Define the number of seconds to wait after finding a core in order to determine if the core is still being written.
Define the number of minutes to wait between search cycles
Specify if the core files should be deleted after report.
0 = No 1 = Yes
NOTE: Until the core file is deleted, it is reported each time crashreporter is restarted.
Specify if the report directory should be deleted after the report. Useful in order to view core reports on box.
0 = No 1 = Yes
NOTE: If not deleted, the directory will be included in each subsequent package.
Specify whether debugging messages are turned on or off in the crashreporter logging output.