This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base Archive
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • NetWitness Knowledge Base Archive
  • NetWitness ESA stopped consuming from concentrators after upgrading
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

NetWitness ESA stopped consuming from concentrators after upgrading

Article Number

000040010

Applies To

Product Set: NetWitness Platform
Product/Service Type: Security Analytics Server
Version/Condition: 11.5.x
Platform: CentOS
O/S Version: 7
 

Issue

After upgrading from 11.3.x to 11.5.x, the ESA service stopped aggregating data from the source Concentrators.
/var/log/netwitness/correlation-server/correlation-server.log shows warnings like below.
WARN c.r.n.s.p.DefaultRecordStreamPolicy|Source admin@<Concentrator_IP>:50005 reported an error, retry after 10 seconds. Error: com.rsa.netwitness.streams.RecordStreamException: admin@<Concentrator_IP>:50005:java.nio.channels.UnresolvedAddressException
Running 'curl -v <Concentrator_IP>:50005' command from the ESA hosts confirms a successful connection to the concentrator.

 

Cause

The issue may occur when /etc/hosts on the ESA host does not contain the UUID and IP entry of the source Concentrators.
 

Resolution

In order to resolve the issue, please modify /etc/hosts on the ESA host to include an entry for all source Concentrators in the following format.

<Host IP>   <Host_UUID> <Host_UUID>.netwitness

For example,
10.10.14.41    a71aa275-b95e-4d62-b17d-0c8907cdf0c1 a71aa275-b95e-4d62-b17d-0c8907cdf0c1.netwitness

After making the change, monitor /var/log/netwitness/correlation-server/correlation-server.log to confirm the warning no longer appears and also the Offered Rate under Configure-ESA RULES-Services.
Tags (37)
  • 11.x
  • Appliance
  • Break Fix
  • Break Fix Issue
  • Broken
  • Config
  • Configuration
  • Configuration Help
  • Configuration Issue
  • Configuration Problem
  • Configuring Issue
  • Configuring Problem
  • Customer Support Article
  • ESA
  • ESA Appliance
  • ESA Service
  • Event Stream Analysis
  • Issue
  • Issue Configuring
  • Issues
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • NetWitness
  • NetWitness Appliance
  • NetWitness Platform
  • NW
  • NW Appliance
  • Problem
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Security Analytics
  • Security Analytics
  • Setup Issue
  • SIEM
  • Version 11
  • Version 11.x
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2022-01-13 09:33 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.