This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base
Find answers to your questions and identify resolutions for known issues with knowledge base articles written by NetWitness experts.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Knowledge Base
  • Windows server SFTP collection is not persistent for RSA NetWitness Platform Collector
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content

Windows server SFTP collection is not persistent for RSA NetWitness Platform Collector

Article Number

000001604

Applies To

RSA Product Set: NetWitness Platform
RSA Product/Service Type: Core Appliance
RSA Version/Condition: 11.X,12.X
Platform: CentOS
O/S Version: 7
Product Name: Windows Server
 

Issue

Windows SFTP collection configured using SFTP Document. However, SFTP Collection frequently stops. Manual restart of SFTP Agent service in the Windows server starts collection again.

Cause

This issue is due to the key caching mismatch with the user account.

Resolution

Please follow the below instructions for SFTP collection persistence.

1. Please login to the Windows Server using any user account.
2. Open the command prompt and run the following command from the C:\sasftpagent directory:
psftp -i private.ppk -l sftp -v log_collector_IP_address
      Where:
      private.ppk is the file containing the private key.
      log_collector_IP_address is the IP address of the Log Collector.

4. The system displays a prompt and some choices.
5. After the prompt, you can choose 'g' from the following options:
    - g: Global. If you enter 'g', the fingerprint is installed in the system environment, which is visible to all users.
           Note: that if you enter the global value, you do not need to run the SFTP service as the user that installed the agent: any user can run the SFTP service.
     - l: (lower case L) Local. If you enter 'l', the fingerprint is stored in the HKEY_LOCAL_USER registry hive, visible only to the currently logged-in user (and Administrators).
     - n: Cancel. Cancels the registration procedure.
5. At the psftp prompt, type quit, and press ENTER.
6. Start the SFTP Agent Service from Windows Services Control Panel.
a. Type services.msc on the command line.
b. Start the SA SFTP Agent service.

If no prompt shows to choose the Global option, Please follow the below instructions to delete existing keys cached Globally or Locally.
  1. Go to the Windows Search bar and type Registry Editor to select.
  2. The global keys will be cached in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment
  3. Local keys will be cached in HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\SshHostKeys
  4. Right-click on the keys to display "delete" option to delete the key. 
  5. Then retry the above key caching steps to choose Global option.
Tags (32)
  • 11.x
  • Appliance
  • Auth
  • Auth Issue
  • Authentication
  • Authentication Issue
  • Break Fix
  • Break Fix Issue
  • Broken
  • Core Appliance
  • Customer Support Article
  • Issue
  • Issues
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Log Collection
  • Log Collector
  • Login Issue
  • NetWitness
  • NetWitness Appliance
  • NetWitness Platform
  • NW
  • NW Appliance
  • NwLogCollector
  • Problem
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Security Analytics
  • Security Analytics
  • SIEM
  • Version 11.x
1 Like
Was this article helpful? Yes No
No ratings

In this article

Version history
Last update:
‎2023-06-21 02:42 PM
Updated by:
Administrator nwinfotech Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.