Article Number
000002792
Applies To
RSA Product Set: Security Analytics
RSA Product/Service Type: Virtual Log Collector (VLC), SFTPAgent
RSA Version/Condition: 10.4.1.x, 10.5.x
Platform: CentOS
O/S Version: EL6
Issue
In some situations, it may be necessary to send logs in the gz formats originally generated by the Event Source rather than log, txt or XML formats.
The Standard Configuration of SFTPAgent does not understand anything except for simple ASCII to send the files to Log Collector or VLC. Instead, it treats the gz files as simple text and hence it sends corrupt files.
Resolution
The solution to this issue is to treat the gz files as binary streams by setting the following parameter in the sftpagent.conf file:
dir0.binary=true
The steps to do this are as follows:
- Stop File Collection on the VLC or Log Collector.
- Stop the agent service.
- Backup and Delete the POS directory in the agent installation directory( Directory that SFTPAgent writes position marker files to) if there is any.
- Add the the following flags in sftpagent.conf:
dir0.binary=true
dir0.compression=false
dir0.has_header=false
- Start the sftpagent.
- Start the File Collection on the VLC or Log Collector.
If you are unsure of any of the steps above or experience any issues, contact RSA Support and quote this article number for further assistance.