Article Number
000031473
Applies To
RSA Product Set: Security Management, Security Analytics
RSA Product/Service Type: SecOps, Event Stream Analysis (ESA), Incident Management (SA IM)
RSA Version/Condition: SecOps 1.2; Security Analytics 10.4.x, 10.5.x
Issue
Alerts in ESA are firing but nothing is making it to the Incident Management component and nothing is being output to SecOps.
Cause
This issue occurs because the "Forward Alerts on Message Bus" option is not selected on the ESA appliance.
Resolution
To resolve the issue, perform the steps below.
- Log into the Security Analytics UI as an administrative user.
- Navigate to Administration -> Services.
- Click on the red Actions button for the ESA service and select View -> Config.
- Click on the Advanced tab.
- Check the box for the Forward Alerts On Message Bus option and then click the Apply button.
Image description
If you are unsure of any of the steps above or experience any issues, contact RSA Support and quote this article number for further assistance.