CSP central server has stopped monitoring - shows online
the CSP central server has stopped seeing activity from all systems for 3 days now. the only log that is being generated is a 5795787 error that says it succesfully purged events. this log event occurs a few times a day.
No changes occurred on the system prior to this occuring, except the addition of adding 5 new solaris clients to report to the server five days earlier.
The server also had started notating several systems as offline before this occured, but it still recieved and alerting on logs from these systems.
the only log message that I am getting now is:
SOURCE
Agent Name SCSP Manager (REDACTED)
Host Name REDACTED
Host IP Address 127.0.0.1
Agent Version 5.2.0.519
OS Type Windows
Agent Type CSP Manager
EVENT
Event Type Server Status
Category Real Time - Management
Operation DELETE EVENTS
Event Severity Information
Event Priority 1
Agent Priority 75
Event Date 09-Oct-2009 09:42:19 EDT
Post Date 09-Oct-2009 09:42:19 EDT
Post Delay 00:00:00
Event Count 220
Event ID 5795787
DETAILS
Description Deleted 220 REALTIME Events from database based on a 365 day limit and a purge limit of 100000 rows. Duration 0 seconds.
Rule Name Database Event Purge
Disposition Success
Operation DELETE EVENTS
Module SCSP Service
Message ID 60400
Comments
Do we need to answer this?
Do we need to answer this? You did not post any question.
Yes please, my problem is
Yes please, my problem is what is being shown -
thanks -
Troubleshooting SCSP alerts
http://service1.symantec.com/support/intrusiondetectkb.nsf/854fa02b4f5013678825731a007d06af/6a2be9daf7fccceb802574db004e495f?OpenDocument
http://service1.symantec.com/support/intrusiondetectkb.nsf/854fa02b4f5013678825731a007d06af/e49b4763afe749c6882575370059c6e6?OpenDocument
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
Would you like to reply?
Login or Register to post your comment.