2018-04-18 10:18 AM
Hello,
I've recently configured the Kaspersky Security Center using the guide available at https://community.rsa.com/docs/DOC-40208.
We're using the ODBC connection to the database, but I'm not sure if any data is being collected.
Can anyone help me figure out how to check this?
Thank you for your help.
Kind Regards,
Pedro Queirós
2018-04-24 06:25 AM
Because it might be useful for someone with similar questions / problems: check if the user configured to access the DB has all the permissions it requires! 🙂
2018-04-18 10:30 AM
Assuming that the test connect worked, and there is data to be collected....
First. Does the IP or hostname show up under either device.ip or device.host?
Second. On the Log Collector check under /var/netwitness/logcollector/runtime/odbc/eventsources/ You should see a file that references your device. Open the file and see if the event traking id section is filled out.
If the file has the proper date or tracking ID, I would open SQL manager and maker sure there is new data in there post collection setup time.
Can you check those and report back?
Thanks
Dave
2018-04-18 11:27 AM
Hello Dave,
Thank you for your quick reply.
Yes, I got a "Test connection successful" message when setting up the source. Going through your suggestions:
1) I couldn't find the device IP or hostname in the mentioned meta keys.
2) The folder "odbc" doesn't exist under "/var/netwitness/logcollector/runtime/".
What am I doing wrong? Do I need to restart the log collector?
Kind Regards,
Pedro Queirós
2018-04-18 11:57 AM
Let me know if you would like to have a webex with me
2018-04-18 12:26 PM
Yes please 🙂
2018-04-18 12:39 PM
email me at dave dot glover at rsa dot com
2018-04-24 06:25 AM
Because it might be useful for someone with similar questions / problems: check if the user configured to access the DB has all the permissions it requires! 🙂
2022-08-17 07:14 AM
Hi DaveGlover,
I am facing the same problem ODBC connectivity test is passed but i am not receiving the logs for Kaspersky security center version 13.2 and i am RSA SIEM version is 13.0.2.
I am not sure what to do need your guiadacne.
Thanks