2015-11-10 12:31 AM
Dear All,
Below is the error message which I am getting after integrating of the machine on Windows Legacy in RSA SA.
So after every attempt of integrating this new event source, I could see only one log in investigation and then it get stoppped after a while and the same below error message start coming if I check under Windows Legacy logs.
"[windows.EAIL.WVM****************] [starting] Collection state not found, normal for first collection attempt from an event source: c:\NetWitness\ng\logcollector\runtime\/windowslegacy/eventsources/windows.EAIL.WVM*************.xml: cannot open file"
Does anyone have any idea regarding this to get this resolved at the earliest. Thanks in advance.
Regards,
Deepanshu Sood.
2015-11-18 11:19 PM
Hi Rasnick,
I believe I am so close to solve that issue, I noticed on the event source itself that event logging service getting crashed after generating one single event.
So that’s why SA is unable to collect the logs.
Will check with the Windows team on this.
Thanks for your response.
Thanks,
Deepanshu Sood | Technical Consultant
2015-11-17 09:01 AM
I have seen this one before.
What is the Windows event source? Version?
Also, can you send a screen shot of your SA configuration for that event source?
2015-11-18 11:19 PM
Hi Rasnick,
I believe I am so close to solve that issue, I noticed on the event source itself that event logging service getting crashed after generating one single event.
So that’s why SA is unable to collect the logs.
Will check with the Windows team on this.
Thanks for your response.
Thanks,
Deepanshu Sood | Technical Consultant