2014-09-08 02:37 AM
Hi all,
Im facing with VLC issue which after added in SA, it continuesly showed error- /var/log/messages
Sep 8 10:25:20 vlc-remote nw[2414]: [AMQPClientBase] [failure] An error occurred creating an AMQP channel: Error in opening SSL/TLS connection for socket
Sep 8 10:25:20 vlc-remote nw[2414]: [MessageBrokerLogReceiver] [warning] Unable to start AMQP Log Receiver: Error in opening SSL/TLS connection for socket
Sep 8 10:25:20 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/queues
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/shovels
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/nodes
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/connections
Sep 8 10:25:21 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:22 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:23 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
and from logcollector\@localhost.log :
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
application: mochiweb
"Accept failed error"
"{error,ekeyfile}"
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
SSL: 1112: error:[] /etc/netwitness/ng/rabbitmq/ssl/keys/privkey.pem
[{ssl_connection,init_private_key,5},
{ssl_connection,ssl_init,2},
{ssl_connection,init,1},
{gen_fsm,init_it,6},
{proc_lib,init_p_do_apply,3}]
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
application: mochiweb
"Accept failed error"
"{error,ekeyfile}"
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
error on AMQP connection <0.5490.0>: {ssl_upgrade_error,ekeyfile}
(END)
My VLC is a for lab testing. I installed using sainstall-10.2.1.1893-44-usb.iso the rpm package provided, RSA_Security_Analytics_Log_Collector_10.0.5.2.zip and upgrade version 10.3.3 SA-LC.zip.
After installed, VLC can be added in SA perfectly but it showing the error above.
I can see log that certificate added to VLC
Sep 5 15:34:44 vlc-remote nw[5573]: [EventBroker] [info] The certificate 14c0407343b3a1f71a06e19dd9cd02ce was added.
Sep 5 15:34:49 vlc-remote nw[5573]: [MessageBroker] [info] info 2014-09-05T07.34.46Z Certificate at "/etc/netwitness/ng/rabbitmq/ssl/keys/cacert.pem" will expire on 2015:07:21T07:29:15 (in 318 days, 15 hours, 54 minutes, and 29 seconds)
I tried configure pull and push but still error log generated.
1-Is there an OVA version for latest VLC? so i no need to install 10.0xx version?
2-How to generate the cert without reinstalling the package?
3-Any idea how to solve my issue ?
thank you
2014-09-08 06:35 AM
You can regenerate the certificate by performing the following:
Administration --> Devices --> Select Log Collector --> Explore --> event-broker --> ssl --> (Right-Click) Properties --> (from drop down) rekey
2014-09-08 09:01 PM
Hi Lee,
The key regenerated, unfortunately the error log still showing up. I also try reset eventbroker but still the same.
I doubt if this due to installation.
Sep 8 19:21:46 vlc-remote init: rabbitmq main process (1896) killed by TERM signal
Sep 8 19:21:46 vlc-remote nw[1102]: [Engine] [info] Child process 2824 sent signal code: exited, child exit code: 0
Sep 8 19:21:46 vlc-remote nw[1102]: [Engine] [info] Child process 2825 sent signal code: exited, child exit code: 0
Sep 8 19:21:46 vlc-remote nw[1102]: [EventBroker] [info] Regenerated the private key and certificate for the event broker.
2014-09-10 07:23 AM
2014-10-14 03:47 AM
We had the same issue. We solved it by removing and "re-adding" the VLC. This :
- flushed its AMQP channel / queue and allowed the collection to start
- initiates a handshake between the server and the VLC which exchanging credentials and SSL certificates
2015-02-03 01:59 AM
Hello Atreide
Hope you are doing well.
I am facing an challenge while adding the log collectors ip address in the VLC>Config>Log Collectors tab.
So for this reason I am unable to achieve the AIO for logs failover.
My motive is if my first Log decoder ( on AIO1) went down then automatically the VLC start pushing the logs to the second AIO ( which is on AIO 2). But I am not able to achieve the same. Kindly suggest if you have any idea about the same.
and as a part of troubleshooting the logs i find the below logs which menor has also shared.
Sep 8 10:25:20 vlc-remote nw[2414]: [AMQPClientBase] [failure] An error occurred creating an AMQP channel: Error in opening SSL/TLS connection for socket
Sep 8 10:25:20 vlc-remote nw[2414]: [MessageBrokerLogReceiver] [warning] Unable to start AMQP Log Receiver: Error in opening SSL/TLS connection for socket
Sep 8 10:25:20 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/queues
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/shovels
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/nodes
Sep 8 10:25:21 vlc-remote nw[2414]: [MessageBrokerStats] [failure] Message-Broker Statistics: failed to get statistics /api/connections
Sep 8 10:25:21 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:22 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
Sep 8 10:25:23 vlc-remote nw[2414]: [EventBroker] [failure] failure in updating statistics for: No such node (stats)
and from logcollector\@localhost.log :
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
application: mochiweb
"Accept failed error"
"{error,ekeyfile}"
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
SSL: 1112: error:[] /etc/netwitness/ng/rabbitmq/ssl/keys/privkey.pem
[{ssl_connection,init_private_key,5},
{ssl_connection,ssl_init,2},
{ssl_connection,init,1},
{gen_fsm,init_it,6},
{proc_lib,init_p_do_apply,3}]
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
application: mochiweb
"Accept failed error"
"{error,ekeyfile}"
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
{mochiweb_socket_server,297,{acceptor_error,{error,accept_failed}}}
=ERROR REPORT==== 8-Sep-2014::07:43:21 ===
error on AMQP connection <0.5490.0>: {ssl_upgrade_error,ekeyfile}
(END)
If anyone have the solution then kindly share the same ASAP. Thanks to all in advance.
Regards,
Deepanshu Sood.
2015-02-12 06:52 AM
hello Menor,
Plz suggest how you have resolved this issue.
I am facing the same issue with my VLC and LC both..
Even tough I my appliances didn't get discovered under the Appliances tab in RSA SA. I have manually added the same and also not able to add their local services like Malware Analysis, IM, IPDB, RE.
Plz suggest how I resolve the same, because after doing so many integration of event sources I am not able to collect any of single log from any of the single event source.
Plz suggest. I will so thankful of you.
Regards,
Deepanshu Sood.
2015-04-07 10:10 AM
Hi Deepanshu,
sorry i was on long holiday. so how was it? do you able to get logs? as i updated in the answer i install the nw-erlang and stop / start the rabbitmq and nwlogcollector. but i think this for 10.3 version.
2015-05-24 05:50 AM
Hi Lee,
Hope you are doing well.
Will you kindly provide me the suggest me the steps that how to re-provision the certificate in between the head appliance and it's other components.
I am still facing the issue in my almost my every VLC regarding the certificate error but after looking for some of the solution regarding the AMQP error still I am not able to resolve the issue.
Due to this error I am almost losing my so much data from more than 10 VLC's.
Please share the exact step by step to re-provision the certificate on VLC with SA.
It would be an great help. Thanks.
Regards,
Deepanshu Sood.
2015-05-26 04:01 AM
Hi Deepanshu,
I don't think re-provisioning the certificate between the SA and VLC will resolve your issue and it is a lot of work without proper support.
Did you try to rekey like I stated before?